!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

696 Members
Coordination and triage of security issues in nixpkgs215 Servers

Load older messages


SenderMessageTime
20 Jul 2021
@hxliew:matrix.orghxliew joined the room.02:16:26
@janne.hess:helsinki-systems.dedas_jDOS in systemd: https://www.openwall.com/lists/oss-security/2021/07/20/212:52:25
@janne.hess:helsinki-systems.dedas_jPatch: https://github.com/systemd/systemd/pull/2025612:52:37
@janne.hess:helsinki-systems.dedas_jHm the mentioned kernel vuln is not so good either…12:58:09
@andreas.schraegle:helsinki-systems.deajs124
In reply to @janne.hess:helsinki-systems.de
Patch: https://github.com/systemd/systemd/pull/20256

As a quick-fix, this should work:

  systemd.package = pkgs.systemd.overrideAttrs (oA: {
    patches = (oA.patches or []) ++ [(pkgs.fetchpatch {
      url = "https://github.com/systemd/systemd/commit/441e0115646d54f080e5c3bb0ba477c892861ab9.patch";
      sha256 = "1g1lk95igaadg67kah9bpi4zsc01rg398sd1247ghjsvl5hxn4v4";
    })];
  });
13:00:34
@hexa:lossy.networkhexa are you going to create a pr or are we defering to #systemd:nixos.org? 13:12:51
@janne.hess:helsinki-systems.dedas_jI can do a PR. is this staging material?13:24:48
@janne.hess:helsinki-systems.dedas_j * I can do a PR. ~~is this staging material?~~13:27:34
@janne.hess:helsinki-systems.dedas_j * I can do a PR. is this staging material?13:27:37
@janne.hess:helsinki-systems.dedas_j * PR: https://github.com/NixOS/nixpkgs/pull/13077913:29:43
@qyliss:fairydust.spaceAlyssa Rosshttps://lwn.net/Articles/863586/16:00:02
@qyliss:fairydust.spaceAlyssa Rosslocal root vuln in Linux16:00:08
@janne.hess:helsinki-systems.dedas_j Yup, that goes along with the systemd vuln… But I was not sure how to apply the patch to all kernels 16:00:42
@qyliss:fairydust.spaceAlyssa Rossthey're in today's stable releases16:01:00
@janne.hess:helsinki-systems.dedas_jah great16:01:06
@qyliss:fairydust.spaceAlyssa Rossso it's just a stable kernel update as usual16:01:14
@qyliss:fairydust.spaceAlyssa Rossjanne.hess: https://github.com/NixOS/nixpkgs/pull/13080716:05:33
@hexa:lossy.networkhexait's usually not worth looking into kernel vulns, because we bump them often enough and they will be released sooner or later16:09:43
@qyliss:fairydust.spaceAlyssa Rossthis seems to be a particularly serious one16:10:09
@hexa:lossy.networkhexawhich is why it was coordinated and promtly released on a schedule16:10:27
@hexa:lossy.networkhexa * which is why it was coordinated and promptly released on a schedule16:10:35
@andreas.schraegle:helsinki-systems.deajs124
In reply to @hexa:lossy.network
it's usually not worth looking into kernel vulns, because we bump them often enough and they will be released sooner or later
also, you need to reboot to apply them. our reboot schedule for a bunch of systems is every half year for the release upgrade.
16:12:05
@hexa:lossy.networkhexayeah rebooting is messy :D16:12:28
@philipp:xndr.dephilippBut the absolutely best feeling is to reboot a compelx system and it just coming back up without any issues.16:13:18
@sumner:sumnerevans.comsumner left the room.21:42:19
21 Jul 2021
@genevino:matrix.orgArminio Genevino joined the room.20:25:46
@noch3:matrix.orgElliot joined the room.20:25:46
@genevino:matrix.orgArminio Genevinoo/20:25:50
@noch3:matrix.orgElliotIs there a detailed writeup of how NixOS stacks up against other distros wrt to security? 20:26:10
@nixinator:nixos.devnixinator
In reply to @noch3:matrix.org
Is there a detailed writeup of how NixOS stacks up against other distros wrt to security?
i can't think of one of the top of my braincase, but do you have a specific questions?
21:20:27

There are no newer messages yet.


Back to Room ListRoom Version: 6