!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

664 Members
Coordination and triage of security issues in nixpkgs212 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
16 May 2025
@winter:catgirl.cloudWinter joined the room.01:58:58
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2025/05/16/7 glibc ma27 23:06:10
@emilazy:matrix.orgemilyI suspect the only static setuid program on 90% of NixOS systems is our wrapper?23:06:54
@emilazy:matrix.orgemily which hopefully doesn't dlopen 23:06:58
@emilazy:matrix.orgemilywell, 90% is probably way too low for that figure. also sorry, forgot this was triage room23:07:16
17 May 2025
@s-rein:basketweavers.nets-rein joined the room.03:31:56
@aloisw:julia0815.dealoisw The wrapper uses musl and erases LD_LIBRARY_PATH, so NixOS should indeed be unaffected. 05:00:12
@ma27:nicht-so.sexyma27 Agreed.
I'll prepare an update todya nonetheless since people are using nixpkgs to build all kinds of stuff.
08:12:34
@vcunat:matrix.orgvcunat Sounds OK for the normal staging* workflow. 08:34:01
@k900:0upti.meK900What's the plan for the next cycle?08:36:37
@k900:0upti.meK900I've got Mesa 25.1.1 and Qt 6.9.1 next week08:36:51
@qyliss:fairydust.spaceAlyssa RossStill looking for Darwin testing on the Meson upgrade https://github.com/NixOS/nixpkgs/pull/40275208:37:33
@qyliss:fairydust.spaceAlyssa RossBut this is the wrong room08:44:58
@ma27:nicht-so.sexyma27

OK we don't have to do anything btw: the advisory states

Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39)

the commit is from 2023 and part of the glibc we're shipping.

08:58:36
@k900:0upti.meK900https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v12:23:49
@k900:0upti.meK900Ayylmao12:24:09
@tgerbet:matrix.orgtgerbetFixed in https://github.com/NixOS/nixpkgs/pull/400278 and https://github.com/NixOS/nixpkgs/pull/403432 It looks like they did not update the fixed version field in the advisory12:26:11
@k900:0upti.meK900Ayylmao, but different 12:27:29
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://github.com/NixOS/nixpkgs/pull/401409 I still have an open security fix PR that noone seems to want to review...14:29:27
@oddlama:matrix.orgoddlama changed their display name from oddlama to Malte.20:12:23
18 May 2025
@k900:0upti.meK900https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/14:06:39
@k900:0upti.meK900 @hexa:lossy.network 14:06:43
@me:linj.techlinjfixed in https://github.com/NixOS/nixpkgs/pull/40823614:07:52
@k900:0upti.meK900Cool 14:08:29
@hexa:lossy.networkhexastill testing on 24.1114:08:58
19 May 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Can we get a merge on https://github.com/NixOS/nixpkgs/pull/408524? Its analogous to the firefox update and i'd really rather have that.... Yes yes, we are on topic with browser forks, but i can't commit this (yet)14:56:55
@oak:universumi.fioak 🏳️‍🌈♥️ changed their display name from oak 🫱⭕🫲 to oak.10:59:05
@hexa:lossy.networkhexa note that we started requiring an active committer on the maintainers list for browsers cough 14:57:48

Show newer messages


Back to Room ListRoom Version: 6