!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

703 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22218 Servers

Load older messages


SenderMessageTime
8 May 2026
@pyrox:pyrox.devdish [Fox/It/She]sigh21:40:41
@pyrox:pyrox.devdish [Fox/It/She]tl;dr io_uring ZCRX freelist LPE21:40:50
@pyrox:pyrox.devdish [Fox/It/She]* tl;dr io_uring ZCRX freelist LPE, affects 6.15 -> 6.1921:41:13
@pyrox:pyrox.devdish [Fox/It/She]but also requires CAP_NET_ADMIN so shouldn't be too much of an issue21:41:34
@pyrox:pyrox.devdish [Fox/It/She] * but also requires CAP_NET_ADMIN and a NIC that supports zero copy recieve(ZCRX) so shouldn't be too much of an issue 21:42:03
@pyrox:pyrox.devdish [Fox/It/She] * but also requires CAP_NET_ADMIN, a NIC that supports zero copy recieve(ZCRX), and kernel configured with io_uring zcrx enabled so shouldn't be too much of an issue 21:42:30
@numinit:matrix.orgMorgan (@numinit)Nice, io_uring, the source of like over half of Android bug bounties over the past couple years21:42:59
@pyrox:pyrox.devdish [Fox/It/She] okay i think this is pretty much a nonissue since you need all the above to write OOB, but then CAP_SYS_ADMIN to execute so... seems like you basically need root and/or elevated privs so... 21:43:54
@numinit:matrix.orgMorgan (@numinit)

https://security.googleblog.com/2023/06/learnings-from-kctf-vrps-42-linux.html

Wish there was a dumpster fire emoji anyway

21:44:55
@pyrox:pyrox.devdish [Fox/It/She] πŸ”₯ πŸ—‘οΈ 21:46:25
@numinit:matrix.orgMorgan (@numinit)

"we paid out around 1 million USD for io_uring alone"

πŸ’ΈπŸ”₯

21:47:06
@sandro:supersandro.deSandro 🐧One of the oauth2-proxy CVEs was only partically addressed and one of the recommended arguments to set was impossible to be defined https://github.com/NixOS/nixpkgs/pull/51821123:16:07
@sandro:supersandro.deSandro 🐧* One of the oauth2-proxy CVEs was only partically addressed and one of the recommended arguments to set was impossible to be defined in the nixos module https://github.com/NixOS/nixpkgs/pull/51821123:17:56
9 May 2026
@pyrox:pyrox.devdish [Fox/It/She] Gitpython security bump: https://github.com/NixOS/nixpkgs/pull/518443 17:20:00
11 May 2026
@kuflierl:matrix.orgkuflierl'high' severtiy cve in python library https://github.com/NixOS/nixpkgs/pull/51879802:28:11
@tgerbet:matrix.orgtgerbetDNSMasq coordinated release (cache poisoning, privesc...) https://www.kb.cert.org/vuls/id/471747 https://github.com/NixOS/nixpkgs/pull/51908217:34:09
@hexa:lossy.networkhexa

dnsmasq has released version 2.93 to fix the above vulnerabilities

17:36:23
@hexa:lossy.networkhexa

dnsmasq: 2.92 -> 2.92rel2

17:36:33
@hexa:lossy.networkhexahttps://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html17:37:29
@hexa:lossy.networkhexa

With luck, 2.93 could be out in a week or so.

17:37:33
@tgerbet:matrix.orgtgerbetRequested an update of the CERT/CC advisory in the internal case...17:40:14
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51843023:24:08
12 May 2026
@harinn:matrix.orgHarinn joined the room.18:14:40
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51950218:32:28
13 May 2026
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51988219:12:05
@numinit:matrix.orgMorgan (@numinit)

https://depthfirst.com/nginx-rift

FYI, nginx 😬, seems to trigger with captures in rewrite

19:15:16
@tgerbet:matrix.orgtgerbethttps://nginx.org/en/CHANGES https://nginx.org/en/CHANGES-1.30 There are also other sec issues in the releases nginxMainline will need a 1.29 -> 1.31 bump. It would be nice if someone could handle it, I have done the last nginx upgrades but I'm not close to a laptop until tomorrow night19:23:09
@numinit:matrix.orgMorgan (@numinit)It's looking like a "tonight" thing for me (so several hours)19:23:44
@hexa:lossy.networkhexahttps://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/19:35:01
@hexa:lossy.networkhexa ma27 19:35:22

There are no newer messages yet.


Back to Room ListRoom Version: 6