
CVE-2026-6766: Mozilla NSS. tls13_AEAD() did `inLen - tagLen` before checking length. A 5-byte QUIC record underflowed to a ~4GB offset -> wild-pointer SEGV. Moderate in Firefox. ASAN first. Report second. Fixed in Firefox 150.
Post summary
A new Mozilla NSS TLS 1.3 underflow causes a wild‑pointer segmentation fault; the issue is moderately severe, was reported via ASAN, and has been fixed in Firefox 150.

