!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

704 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
29 Mar 2024
@clefru:matrix.orgclefruRedacted or Malformed Event08:53:25
@clefru:matrix.orgclefru* FYI from what I see, the two 0 days for Google Chrome published on Tuesday are still unpatched in release-23.11. 08:53:45
@clefru:matrix.orgclefruRedacted or Malformed Event09:00:49
@clefru:matrix.orgclefruSorry ignore that.. I am tracking nixos-23.11 and not release-23.1109:05:50
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2024/03/29/4 16:12:46
@phileas:asra.grsyd installs gentoo (they/them)
In reply to @hexa:lossy.network
https://www.openwall.com/lists/oss-security/2024/03/29/4
b) argv[0] needs to be /usr/sbin/sshd
16:15:35
@phileas:asra.grsyd installs gentoo (they/them)
In reply to @hexa:lossy.network
https://www.openwall.com/lists/oss-security/2024/03/29/4
*

b) argv[0] needs to be /usr/sbin/sshd

ldd $(which sshd) | grep -i lzma doesn't link against lzma

16:19:17
@phileas:asra.grsyd installs gentoo (they/them) *

b) argv[0] needs to be /usr/sbin/sshd

ldd $(which sshd) | grep -i lzma doesn't link against lzma

https://github.com/NixOS/nixpkgs/blob/master/pkgs/tools/compression/xz/default.nix

is on the affected version 5.6.1

16:20:24
@phileas:asra.grsyd installs gentoo (they/them) *

b) argv[0] needs to be /usr/sbin/sshd

ldd $(which sshd) | grep -i lzma doesn't link against lzma

https://github.com/NixOS/nixpkgs/blob/master/pkgs/tools/compression/xz/default.nix

is on the affected version 5.6.1 (5.4.4 on 23.11)

16:21:00
@phileas:asra.grsyd installs gentoo (they/them) *

b) argv[0] needs to be /usr/sbin/sshd

ldd $(which sshd) | grep -i lzma doesn't link against lzma

https://github.com/NixOS/nixpkgs/blob/master/pkgs/tools/compression/xz/default.nix

is on the affected version 5.6.1 (5.4.4 on 23.11)

Thank you hexa https://github.com/NixOS/nixpkgs/pull/300028

16:22:08
@julienmalka:matrix.orgJulienJust saw that as well, is there a specific reason we are not building xz from the "source code" links generated from github ? If I understand correctly part of the backdoor is not present in there 16:38:11
@vcunat:matrix.orgvcunatBecause release tarballs need less dependencies to build.16:39:31
@raitobezarius:matrix.orgraitobezarius
In reply to @julienmalka:matrix.org
Just saw that as well, is there a specific reason we are not building xz from the "source code" links generated from github ? If I understand correctly part of the backdoor is not present in there
#security-discuss:nixos.org
16:39:38
@vcunat:matrix.orgvcunat * Because release tarballs need less dependencies to build from. 16:39:55
@tgerbet:matrix.orgtgerbetAnd the source code tarball generated by GH automatically are not stable16:40:28
@vcunat:matrix.orgvcunatWe have tools for that.16:40:55
@vcunat:matrix.orgvcunatHashing the unpacked directory tree instead.16:41:07
@vcunat:matrix.orgvcunat Dependency on autoreconfHook can be bothersome, especially for packages involved in stdenv bootstrapping. 16:41:42
@m00dy:matrix.orgmoody joined the room.17:20:21
@pareto-optimal-dev:matrix.orgpareto-optimal-dev joined the room.17:25:15
@mjm:midna.devmjm joined the room.17:26:08
@mjm:midna.devmjm 17:31:16
@Minijackson:matrix.orgMinijackson joined the room.17:33:44
@christian:kampka.netChristian joined the room.17:38:47
@hemant:cyberia.clubhemant (he/they) joined the room.17:48:51
@bear454:librem.one@bear454:librem.one joined the room.18:28:44
@mattleon:matrix.orgmattleon joined the room.18:31:48
@robgssp:matrix.orgrobgssp joined the room.18:32:48
@bear454:librem.one@bear454:librem.one left the room.18:32:54
@dp:anarchyislove.xyzDustin Plattner joined the room.18:45:10

Show newer messages


Back to Room ListRoom Version: 6