Critical Heap Buffer Overflow Vulnerabilities in Fedora NSS and Firefox

Critical Heap Buffer Overflow Vulnerabilities in Fedora NSS and Firefox

First seen 3 Sep 2026, 07:00 UTC Linuxsecuritywww.mozilla.org 60.6

Article Content

Browse articles
ThreatCluster

Recent updates for Fedora 43 and 44 address critical heap buffer overflow vulnerabilities in Network Security Services (NSS) and Mozilla Firefox. The vulnerabilities, identified as Bug 1869493, affect versions 3.127.0 of NSS and Firefox 155.0. Exploitation could lead to unauthorized access or manipulation of sensitive data. Users are urged to update their systems immediately to mitigate risks. The vulnerabilities are associated with improper handling of memory, which could allow attackers to execute arbitrary code. The patches are available through the 'dnf' update program. No active exploitation has been confirmed in the wild as of the latest reports. The updates were released on September 3, 2026.

Key Points: • Critical heap buffer overflow vulnerabilities in NSS and Firefox require immediate patching. • Affected versions include NSS 3.127.0 and Firefox 155.0 on Fedora 43 and 44. • No active exploitation has been confirmed, but the vulnerabilities pose significant risks.

Timeline

2026-09-03
Patches released for NSS and Firefox
Fedora released updates for NSS and Firefox addressing critical heap buffer overflow vulnerabilities.
Linuxsecurity
2026-09-03
Vulnerability details disclosed
Bug 1869493 identified heap-buffer overflow in NSS affecting security applications.
Linuxsecurity
2026-09-03
Firefox vulnerability reported
Heap overflow vulnerabilities in Firefox 155.0 were also patched in the latest update.
Linuxsecurity