!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

675 Members
Coordination and triage of security issues in nixpkgs211 Servers

Load older messages


SenderMessageTime
8 Oct 2025
@j-k:matrix.orgj-k

https://seclists.org/oss-sec/2025/q4/18

Go 1.24.8 and 1.25.2

These minor releases include 10 security fixes

08:08:32
@k900:0upti.meK900Merged on staging-next minutes ago08:09:22
@felix.schroeter:scs.ems.hostFelix Schröter changed their display name from Felix Schröter (🌄 29.09. – 05.10.) to Felix Schröter.13:09:33
9 Oct 2025
@srhb:matrix.orgsrhb set a profile picture.07:08:03
@stefan.nuernberger:cyberus-technology.deStefan Nürnberger joined the room.09:39:25
@notgne2:wizbos.club@notgne2:wizbos.club left the room.20:10:13
10 Oct 2025
@niklaskorz:matrix.orgniklaskorzhttps://nvidia.custhelp.com/app/answers/detail/a_id/5703/~/security-bulletin%3A-nvidia-gpu-display-drivers---october-202512:25:46
@niklaskorz:matrix.orgniklaskorzversion we're shipping as legacy_535 is again affected but I haven't checked yet if the CVE is relevant to NixOS12:26:05
@niklaskorz:matrix.orgniklaskorz (personally I'd be in favor of dropping 535 for NixOS 25.11, the only user I'm aware of is @doronbehar, who's not in this channel I think; but we can discuss that in #security-discuss:nixos.org) 12:26:53
@niklaskorz:matrix.orgniklaskorz570 driver version we're shipping on 25.05 (570.153.02) is also vulnerable (570.195.03 is available with the fixes)12:28:32
@niklaskorz:matrix.orgniklaskorzdefault driver on unstable is not affected / already has the fixes12:29:15
@leona:leona.isleonafound a not maintained TLS impl version (mbedtls), marked as vulnerable for now: https://github.com/NixOS/nixpkgs/pull/45068814:25:34
@leona:leona.isleona* found a not maintained TLS impl version (mbedtls_2), marked as vulnerable for now: https://github.com/NixOS/nixpkgs/pull/45068814:26:09
@niklaskorz:matrix.orgniklaskorzhttps://github.com/NixOS/nixpkgs/pull/45072916:48:13
11 Oct 2025
@midischwarz12:libg.somidischwarz12 joined the room.21:01:41
12 Oct 2025
@midischwarz12:libg.somidischwarz12 removed their profile picture.02:45:02
@midischwarz12:libg.somidischwarz12 set a profile picture.02:45:11
@anton:gersthof.comAnton (he/him) changed their display name from Anton to Anton (he/him).13:18:01
13 Oct 2025
@niklaskorz:matrix.orgniklaskorznvidia 535 update with beforementioned CVE fixes: https://github.com/NixOS/nixpkgs/pull/45161809:43:33
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/2621:54:56
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2025/q4/26 boringssl21:55:02
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/27 poppler21:55:17
@hexa:lossy.networkhexarequires poppler-25.10.022:27:01
@hexa:lossy.networkhexa * requires poppler-25.10.0 (Jan Tojnar) 22:27:09
@hexa:lossy.networkhexahttps://gitlab.freedesktop.org/poppler/poppler/-/commit/4ce27cc826bf90cc8dbbd8a8c87bd913cccd7ec022:27:29
@hexa:lossy.networkhexahttps://webkitgtk.org/security/WSA-2025-0007.html webkitgtk23:11:01
14 Oct 2025
@vcunat:matrix.orgvcunatThe boringssl thread doesn't seem very convincing, i.e. no claim is made that the leak goes beyond key length and similar "uninteresting" parameters.08:56:06
@vcunat:matrix.orgvcunatAll crypto libs will take longer time when using longer keys, I believe. (up to some exceptions maybe when the difference in length is small)08:57:39
@jassu:kumma.juttu.asiaJassukoBeing able to reduce the search space to a specific amount of bits for the private key is a way more information than you might expect. EC priv key is practically a number between 1 and N-1, where N is the order of the curve. For example with P-256 curve you can have a private key that has 253 effective bits in its representation. Knowing this would directly allow you to limit your search space for figuring out the private key to under 1/8 of the full key space. The practical implications as of now probably don't warrant any direct panic or actions, but building cryptography things is generally based on a strict set of design goals and delivering 100% of the promises given, so in that sense this is a timing side channel which can reveal few bits worth of information of the private key whenever an oracle exists that allows the repeated timing measurements. Well worth fixing and updating, even though there would not be need for a panic-mode actions at this point. Besides, all kinds of weakenings left unpatched tend to gather up, and then the day comes when your security gets broken because someone figured a way to use those things together in clever ways.14:57:17
@vcunat:matrix.orgvcunatI don't think that's what the post implied.14:59:02

Show newer messages


Back to Room ListRoom Version: 6