StackPatch is liveSee product

Back to CVE digest
CVE-2026-12318 · cross-distro fix matrix

CVE-2026-12318: Haruto Kimura discovered that NSS had incorrecty handled parsing PKCS#11

Affects 7 Linux releases across 19 (distro × package) combinations. First disclosed: 2026-06-16.

CVSS v3:HIGH · 7.3(NVD-published)

Fix per ecosystem

Each block below is a distro release where CVE-2026-12318 has a known fix. Run the listed command on that distro to remediate.

Ubuntu jammy

Source: Ubuntu USN

  • nss→ fixed in2:3.98-0ubuntu0.22.04.4USN-8481-1
    sudo apt-get install --only-upgrade -y nss
  • libnss3→ fixed in2:3.98-0ubuntu0.22.04.4USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3
  • libnss3-dev→ fixed in2:3.98-0ubuntu0.22.04.4USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-dev
  • libnss3-tools→ fixed in2:3.98-0ubuntu0.22.04.4USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-tools

Ubuntu noble

Source: Ubuntu USN

  • nss→ fixed in2:3.98-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y nss
  • libnss3→ fixed in2:3.98-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3
  • libnss3-dev→ fixed in2:3.98-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-dev
  • libnss3-tools→ fixed in2:3.98-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-tools

Ubuntu questing

Source: Ubuntu USN

  • nss→ fixed in2:3.114-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y nss
  • libnss3→ fixed in2:3.114-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3
  • libnss3-dev→ fixed in2:3.114-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-dev
  • libnss3-tools→ fixed in2:3.114-1ubuntu0.2USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-tools

Ubuntu resolute

Source: Ubuntu USN

  • nss→ fixed in2:3.120-1ubuntu2.1USN-8481-1
    sudo apt-get install --only-upgrade -y nss
  • libnss3→ fixed in2:3.120-1ubuntu2.1USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3
  • libnss3-dev→ fixed in2:3.120-1ubuntu2.1USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-dev
  • libnss3-tools→ fixed in2:3.120-1ubuntu2.1USN-8481-1
    sudo apt-get install --only-upgrade -y libnss3-tools

Debian bullseye

Source: Debian Security Tracker

  • nss→ fixed in2:3.61-1+deb11u6urgency: not yet assigned
    sudo apt-get install --only-upgrade -y nss

Debian bookworm

Source: Debian Security Tracker

  • nss→ fixed in2:3.87.1-1+deb12u3urgency: not yet assigned
    sudo apt-get install --only-upgrade -y nss

Debian trixie

Source: Debian Security Tracker

  • nss→ fixed in2:3.110-1+deb13u3urgency: not yet assigned
    sudo apt-get install --only-upgrade -y nss
Are YOU affected by CVE-2026-12318?

5-second check on your actual server. Reads /etc/os-release, uname -r, and the distro's package manager; matches against this same cross-source index live.

curl https://mindsparkstack.com/scan.sh | bash
Continuous monitoring beats manual checking

CVE-2026-12318dropped silently in your distro's update channel. Every new CVE is the same story. StackPatch runs the matcher hourly against all 5 sources and emails the exact remediation when something new applies to one of your servers. From $9/mo, 14-day free trial, cancel anytime.

See StackPatch (from $9/mo)