Gnoppix Security Announcement - 2026-07-29T20:01:04.814-04:00

Gnoppix Security Issues Emergency Fix for NSS Memory Safety Flaw

GSA-6403-1 patches multiple memory safety bugs in the Network Security Services (NSS) library, posing immediate risk of data corruption or crashes.

Critical Flaw in Cryptographic Library

NSS, the core Mozilla cryptographic library, contained memory safety errors. These bugs could let attackers corrupt memory or crash applications using NSS for encryption or certificate handling.

Gnoppix Versions Affected

  • Gnoppix 23/25 (old stable) and Gnoppix 25 (stable) both require urgent updates.

Immediate Action Required

Update the nss package to version 2:3.110-1~deb12u1 (for Gnoppix 23/25) or 2:3.110-1 (for Gnoppix 25).

Background

Memory safety vulnerabilities in C-based libraries can lead to exploitable conditions. The fix addresses multiple issues discovered during upstream testing. - Please update your systems.