An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. External References: https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/#CVE-2016-9074
Acknowledgments: Name: the Mozilla project Upstream: Franziskus Kiefer
Created nss tracking bugs for this issue: Affects: fedora-all [bug 1396550]
Upstream commit: https://hg.mozilla.org/projects/nss/rev/1e202f0a01b9