!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

717 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
24 Mar 2024
@hexa:lossy.networkhexahttps://gnutls.org/security-new.html#GNUTLS-SA-2023-12-0411:05:08
@hexa:lossy.networkhexa * https://gnutls.org/security-new.html#GNUTLS-SA-2023-12-04 vcunat 11:07:44
@tgerbet:matrix.orgtgerbetUnstable here https://github.com/NixOS/nixpkgs/pull/297657 Taking a look for the backport to stable, looks like the file has been nixpkgs-fmted11:12:44
@hexa:lossy.networkhexaah thanks, for some reason I missed it when I checked the version on staging11:17:38
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/29860411:19:29
@qyliss:fairydust.spaceAlyssa RossSeems to regress musl :(14:31:41
25 Mar 2024
@binarycat:snug.moeネコ joined the room.00:12:11
@binarycat:snug.moeネコhey i found a way to put nulls in strings, unsure if that has security implications, but it should probably be an error?00:14:04
@binarycat:snug.moeネコunsure if i should open an issue on github? could this be used for some sort of buffer overflow attack? idk00:15:48
@admin:nixos.org@admin:nixos.org joined the room.00:23:10
@hexa:lossy.networkhexa can you explain more in #security-discuss:nixos.org 00:23:58
@hexa:lossy.networkhexa * can you explain more in #security-discuss:nixos.org? 00:24:04
@admin:nixos.org@admin:nixos.org left the room.00:30:35
@r_i_s:matrix.orgris_https://github.com/NixOS/nixpkgs/pull/29754720:14:15
@hexa:lossy.networkhexawow, this looks like code copy pasted from home-assistant 😄 20:30:09
@hexa:lossy.networkhexawhich can be explained because bdraco was involved20:30:32
26 Mar 2024
@hexa:lossy.networkhexa https://webkitgtk.org/security/WSA-2024-0002.html Jan Tojnar 03:22:18
@linucifer:envs.net@linucifer:envs.net joined the room.19:09:13
@pinpox:matrix.orgpinpoxNot sure if this is the right place to ask, but are current NixOS versions impacted by https://github.com/Notselwyn/CVE-2024-1086 ? 20:33:53
@k900:0upti.meK900Mo20:34:38
@k900:0upti.meK900* No20:34:45
@k900:0upti.meK900

The exploit affects versions from (including) v5.14 to (including) v6.6, excluding patched branches v5.15.149>, v6.1.76>, v6.6.15>

20:35:11
@r_i_s:matrix.orgris_at last https://github.com/NixOS/nixpkgs/pull/29596723:05:56
27 Mar 2024
@jtojnar:matrix.orgJan Tojnarhttps://github.com/NixOS/nixpkgs/pull/29941705:44:09
@tgerbet:matrix.orgtgerbethttps://www.openwall.com/lists/oss-security/2024/03/27/5 util-linux 2.40 was released with the fix https://github.com/util-linux/util-linux/commit/404b0781f52f7c045ca811b2dceec526408ac25321:06:20
@tgerbet:matrix.orgtgerbetAnd curl 8.7.1 https://github.com/NixOS/nixpkgs/pull/29958021:07:22
@tgerbet:matrix.orgtgerbetWell https://www.openwall.com/lists/oss-security/2024/03/27/7 😅21:48:07
29 Mar 2024
@sebtm:lodere.esSebTM joined the room.04:23:38
@vcunat:matrix.orgvcunathttps://github.com/NixOS/nixpkgs/commit/c2b0bf3dd525#commitcomment-14036563406:36:33
@vcunat:matrix.orgvcunat (in case someone's interested in .mlflow for NixOS 23.11) 06:37:06

Show newer messages


Back to Room ListRoom Version: 6