!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

660 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
10 Jul 2025
@vcunat:matrix.orgvcunat25.05 will probably need to pick the CVE patches. For staging: https://github.com/NixOS/nixpkgs/pull/42409516:38:33
@fr0de_0xa:matrix.orgFred Lahde joined the room.18:48:25
11 Jul 2025
@importantblimp:matrix.orgimportantblimp joined the room.09:54:49
@felix.schroeter:scs.ems.hostFelix Schröter (🎄2025-12-20T00/2026-01-05T00) joined the room.16:58:53
12 Jul 2025
@hexa:lossy.networkhexahttps://github.com/NixOS/nix/security/advisories/GHSA-qc7j-jgf3-qmhg12:15:00
@emilazy:matrix.orgemily handling nixVersions.git 13:22:35
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/42459313:33:13
@emilazy:matrix.orgemilytesting build on Darwin, if someone could get Linux that would be cool13:33:24
@xokdvium:matrix.orgSergei Zimmerman (xokdvium) joined the room.14:08:27
@xokdvium:matrix.orgSergei Zimmerman (xokdvium) Backport bot having issues on emily's PR. Manual backport I've opened at the same time https://github.com/NixOS/nixpkgs/pull/424592.
Will merge when darwin build finishes.
14:10:48
14 Jul 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) *

https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572
https://nvd.nist.gov/vuln/detail/CVE-2025-6816 | https://github.com/HDFGroup/hdf5/issues/5571
https://nvd.nist.gov/vuln/detail/CVE-2025-6750 | https://github.com/HDFGroup/hdf5/issues/5549
https://nvd.nist.gov/vuln/detail/CVE-2025-6516 | https://github.com/HDFGroup/hdf5/issues/5581
https://nvd.nist.gov/vuln/detail/CVE-2025-6270 | https://github.com/HDFGroup/hdf5/issues/5580
https://nvd.nist.gov/vuln/detail/CVE-2025-6269 | https://github.com/HDFGroup/hdf5/issues/5579
https://nvd.nist.gov/vuln/detail/CVE-2025-7069 | https://github.com/HDFGroup/hdf5/issues/5550
https://nvd.nist.gov/vuln/detail/CVE-2025-7068 | https://github.com/HDFGroup/hdf5/issues/5578
https://nvd.nist.gov/vuln/detail/CVE-2025-7067 | https://github.com/HDFGroup/hdf5/issues/5577

hdf5 doesn't have a new release, and none of these CVEs have patches yet either. I'll be watching the issues, i have my own projects that depend on hdf5 (bachelors thesis) but figured i might as well post these here too. Fix will likely only come out in September.

07:07:15
15 Jul 2025
@ginkogruen:matrix.orgginkogruen joined the room.22:54:11
@cnorman:matrix.orgChris Norman joined the room.22:54:12
16 Jul 2025
@teutat3s:pub.solarteutat3shttps://github.com/electron/electron/releases/tag/v37.2.2 | Updated Chromium to 138.0.7204.100 https://github.com/NixOS/nixpkgs/pull/42575010:45:31
@teutat3s:pub.solarteutat3shttps://github.com/NLnetLabs/unbound/releases/tag/release-1.23.1 | fixes the Rebirthday Attack CVE-2025-599411:35:11

Show newer messages


Back to Room ListRoom Version: 6