NSS Vulnerability Poses Risk of Denial of Service and Remote Code Execution

NSS Vulnerability Poses Risk of Denial of Service and Remote Code Execution

First seen 5 Mar 2026, 15:17 UTC UbuntuLinuxsecurity 66.8

Article Content

Browse articles
ThreatCluster

A vulnerability in NSS has been identified that could allow remote attackers to crash the service or execute arbitrary code through specially crafted network traffic. This issue affects multiple versions of Ubuntu, including 14.04 LTS, 16.04 LTS, 18.04 LTS, and 20.04 LTS. The vulnerability arises from improper memory handling during GHASH operations.

Timeline

2026-03-04
USN-8071-1 advisory published, detailing NSS vulnerability
2026-03-05
USN-8071-2 advisory published, providing fixes for affected Ubuntu versions