!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

363 Members
Discussions around Security | Triaging happens in #security:nixos.org126 Servers

Load older messages


SenderMessageTime
5 Oct 2024
@emilazy:matrix.orgemily(doesn't work, but maybe it's useful to you)03:17:31
@elvishjerricco:matrix.orgElvishJerriccothanks03:17:53
@emilazy:matrix.orgemilyrelevant comment about timing / multiple sessions https://matrix.to/#/!NBBFPbiuttRgTqbrcY:nixos.org/$-nf3vPAiCozFLiNCXkzyvCjEZ9W57MT7dOBOLu9ee_U?via=nixos.org&via=matrix.org&via=nixos.dev03:18:05
@emilazy:matrix.orgemilyand pointer to earlier discussion from there03:18:10
@elvishjerricco:matrix.orgElvishJerricco yea, so my guess is that there is some vulnerability here, that's probably quite difficult to take advantage of 03:18:26
@elvishjerricco:matrix.orgElvishJerricco part of it depends on when exactly pam_sm_open_session happens. 03:21:29
@elvishjerricco:matrix.orgElvishJerriccoBut I think you can make that not matter by having a non-gdm session open before gdm-autologin happens03:27:53
@elvishjerricco:matrix.orgElvishJerriccowhich is probably plausible with systemd user lingering03:28:04
@elvishjerricco:matrix.orgElvishJerriccooh that was easier than I thought03:55:46
@elvishjerricco:matrix.orgElvishJerricco emily: you around? 03:55:49
@magic_rb:matrix.redalder.orgmagic_rb changed their profile picture.22:18:06
6 Oct 2024
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/346797 could probably use more opinions/discussion (for once I lean slightly against)12:47:22
@sofo:matrix.org@sofo:matrix.org left the room.15:28:06
@winter:catgirl.cloudWinteryeah i don't like this... i'll write up something17:53:22
@emilazy:matrix.orgemilyi think we have decent consensus to not mark it right now at this point17:57:03
7 Oct 2024
@lehmanator:tchncs.deSam Lehman changed their profile picture.14:24:09
9 Oct 2024
@nickcao:nichi.coNick Caofirefox RCE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/14:12:28
@Valodim:stratum0.orgValodimwhew14:20:57
@emilazy:matrix.orgemily

@hexa:lossy.network

14:30:23
@hexa:lossy.networkhexacool.14:30:33
@vsh:nyantec.comVika Shleina (she/her)
In reply to @nickcao:nichi.co
firefox RCE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/
Is firefox-devedition (131.0b9) vulnerable? Not entirely familiar with Firefox versioning
14:34:54
@hexa:lossy.networkhexavery likely14:35:09
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/34750014:38:25
@vsh:nyantec.comVika Shleina (she/her)
In reply to @hexa:lossy.network
very likely
There is apparently Firefox 132 beta. I could try my hand at bumping this.
14:47:08
@hexa:lossy.networkhexauh, I can push more to my branch14:47:22
@hexa:lossy.networkhexaok, bumped14:51:20
@vsh:nyantec.comVika Shleina (she/her)Thank you! 💖14:51:39
@hexa:lossy.networkhexathe expensive thing is to test the stuff 🙂 14:52:06
@hexa:lossy.networkhexaok, firefox is bumped, tested and backported18:13:40
@hexa:lossy.networkhexaI'm kicking the hydra jobsets next18:13:57

Show newer messages


Back to Room ListRoom Version: 9