!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

662 Members
Coordination and triage of security issues in nixpkgs210 Servers

Load older messages


SenderMessageTime
5 Jun 2025
@vcunat:matrix.orgvcunatI saw https://github.com/NixOS/nixpkgs/pull/41368907:41:52
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Probably more relevant: https://github.com/NixOS/nixpkgs/pull/413987 there is an update, not just patches to cherry-pick08:59:43
@stigo:matrix.orgstigo https://github.com/NixOS/nixpkgs/pull/414219 for CVE-2011-10007 affecting perlPackages.FileFindRule 12:13:00
@b12f:pub.solarb12f changed their display name from b12f to undefined.09:38:08
@b12f:pub.solarb12f changed their display name from undefined to b12f.11:18:22
@mokasin:mokasin.de@mokasin:mokasin.de left the room.18:55:31
@tioan:dunwyn.xyz@tioan:dunwyn.xyz left the room.19:02:18
6 Jun 2025
@arcayr:mischief.expertarcayr changed their profile picture.01:11:39
7 Jun 2025
@deeok:matrix.orgmatrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms) left the room.22:17:28
@deeok:matrix.orgmatrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms) joined the room.23:22:01
8 Jun 2025
@-jb:matrix.org@-jb:matrix.org removed their profile picture.09:16:38
@-jb:matrix.org@-jb:matrix.org removed their display name Jb.09:16:56
@-jb:matrix.org@-jb:matrix.org left the room.09:17:11
9 Jun 2025
@h0nig2k:matrix.orgh0nig2khttps://github.com/NixOS/nixpkgs/issues/415282 for sqlite CVE's related to 25.0512:23:07
@h0nig2k:matrix.orgh0nig2k* https://github.com/NixOS/nixpkgs/issues/415282 for sqlite CVE's related to 25.05, fixes are present for master already12:23:33
@h0nig2k:matrix.orgh0nig2k* https://github.com/NixOS/nixpkgs/issues/415282 for sqlite CVE's related to 25.05, fixes are present for master already but backport PR was closed12:30:06
@konys.synok:matrix.orgKonys Synok joined the room.13:14:21
10 Jun 2025
@teutat3s:pub.solarteutat3s https://github.com/NixOS/nixpkgs/pull/415625 Fixes CVE-2025-48937 18:05:20
@hexa:lossy.networkhexa K900: https://kde.org/info/security/advisory-20250609-1.txt konsole 23:51:04
@hexa:lossy.networkhexa * K900: https://kde.org/info/security/advisory-20250609-1.txt konsole https://proofnet.de/publikationen/konsole_rce.html 23:51:11
11 Jun 2025
@k900:0upti.meK900
In reply to @hexa:lossy.network
K900: https://kde.org/info/security/advisory-20250609-1.txt konsole
Fixed in 25.04.2 so we should be good everywhere
06:23:38
@astodialo:matrix.orgelamon joined the room.15:15:32
@saiko:knifepoint.netKatalin 🔪 changed their profile picture.16:11:59
@saiko:knifepoint.netKatalin 🔪 changed their display name from Katalin 🔪 to Katalin ⚧︎.16:13:21
12 Jun 2025
@sugi:matrix.besaid.desugi changed their profile picture.11:54:22
@stigo:matrix.orgstigoRed Hat just assigned CVEs for these: CVE-2025-5914 CVE-2025-5915 CVE-2025-5916 CVE-2025-5917 CVE-2025-591817:54:47
@stigo:matrix.orgstigo* Red Hat just assigned CVEs for these (in coordination with upstream): CVE-2025-5914 CVE-2025-5915 CVE-2025-5916 CVE-2025-5917 CVE-2025-591817:56:40
@stigo:matrix.orgstigo * Red Hat just recently assigned CVEs for these (in coordination with upstream):
CVE-2025-5914
CVE-2025-5915
CVE-2025-5916
CVE-2025-5917
CVE-2025-5918
18:02:21
13 Jun 2025
@ma27:nicht-so.sexyma27

https://github.com/NixOS/nixpkgs/pull/416357, grafana 12.0.1+security-01 (fixes CVE-2025-3415).
nothing published yet, so I don't really know what this is about.

about to leave, when I'm back I'll also update the package on 24.11.

07:10:29
@ma27:nicht-so.sexyma27 https://github.com/NixOS/nixpkgs/pull/416418 for 24.11 10:37:25

Show newer messages


Back to Room ListRoom Version: 6