The NSS Development Team announces multiple patch releases: * NSS 3.44.2 for NSS 3.44 * NSS 3.46.1 for NSS 3.46
No new functionality is introduced in these releases. The following fixes are included in both releases. Users are encouraged to upgrade. * 1582343 - Soft token MAC verification not constant time * 1577953 - Remove arbitrary HKDF output limit by allocating space as needed NSS 3.44.2 requires NSPR 4.21 or newer. The HG tag is NSS_3_44_2_RTM. NSS 3.44.2 source distributions are available on ftp.mozilla.org for secure HTTPS download: https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_44_2_RTM/src/ Full release notes are available at https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44.2_release_notes NSS 3.46.1 requires NSPR 4.22 or newer. The HG tag is NSS_3_46_1_RTM. NSS 3.46.1 source distributions are available on ftp.mozilla.org for secure HTTPS download: https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_46_1_RTM/src/ Full release notes are available at https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46.1_release_notes -- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-tech-crypto