!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

695 Members
Coordination and triage of security issues in nixpkgs213 Servers

Load older messages


SenderMessageTime
7 Oct 2025
@hexa:lossy.networkhexait is19:11:00
@hexa:lossy.networkhexacan you run the build & test?19:12:02
@hexa:lossy.networkhexathe PR template is a bit too empty for my taste19:12:20
@enzime:nixos.dev@enzime:nixos.dev
In reply to @hexa:lossy.network
can you run the build & test?
I ran nixpkgs-review on both PRs which includes the NixOS VM tests succeeding
19:13:22
@hexa:lossy.networkhexayeah, the PR template is the relevant bit to get an overview though19:13:46
@enzime:nixos.dev@enzime:nixos.dev
In reply to @hexa:lossy.network
yeah, the PR template is the relevant bit to get an overview though
updated
19:14:55
@mdaniels5757:matrix.orgmdaniels5757Mind taking a look at https://github.com/NixOS/nixpkgs/pull/448639? Backport to fix 4 CVEs: 2 unauthenticated vulns that allow reading arbitrary files, 2 authenticated vulns for RCE.22:34:06
8 Oct 2025
@enzime:nixos.dev@enzime:nixos.dev hexa thanks for the review 06:21:45
@enzime:nixos.dev@enzime:nixos.dev left the room.06:21:54
@j-k:matrix.orgj-k

https://seclists.org/oss-sec/2025/q4/18

Go 1.24.8 and 1.25.2

These minor releases include 10 security fixes

08:08:32
@k900:0upti.meK900Merged on staging-next minutes ago08:09:22
@felix.schroeter:scs.ems.hostFelix Schröter changed their display name from Felix Schröter (🌄 29.09. – 05.10.) to Felix Schröter.13:09:33
9 Oct 2025
@srhb:matrix.orgsrhb set a profile picture.07:08:03
@stefan.nuernberger:cyberus-technology.deStefan Nürnberger joined the room.09:39:25
@notgne2:wizbos.club@notgne2:wizbos.club left the room.20:10:13
10 Oct 2025
@niklaskorz:matrix.orgniklaskorzhttps://nvidia.custhelp.com/app/answers/detail/a_id/5703/~/security-bulletin%3A-nvidia-gpu-display-drivers---october-202512:25:46
@niklaskorz:matrix.orgniklaskorzversion we're shipping as legacy_535 is again affected but I haven't checked yet if the CVE is relevant to NixOS12:26:05
@niklaskorz:matrix.orgniklaskorz (personally I'd be in favor of dropping 535 for NixOS 25.11, the only user I'm aware of is @doronbehar, who's not in this channel I think; but we can discuss that in #security-discuss:nixos.org) 12:26:53
@niklaskorz:matrix.orgniklaskorz570 driver version we're shipping on 25.05 (570.153.02) is also vulnerable (570.195.03 is available with the fixes)12:28:32
@niklaskorz:matrix.orgniklaskorzdefault driver on unstable is not affected / already has the fixes12:29:15
@leona:leona.isleonafound a not maintained TLS impl version (mbedtls), marked as vulnerable for now: https://github.com/NixOS/nixpkgs/pull/45068814:25:34
@leona:leona.isleona* found a not maintained TLS impl version (mbedtls_2), marked as vulnerable for now: https://github.com/NixOS/nixpkgs/pull/45068814:26:09
@niklaskorz:matrix.orgniklaskorzhttps://github.com/NixOS/nixpkgs/pull/45072916:48:13
11 Oct 2025
@midischwarz12:libg.somidischwarz12 joined the room.21:01:41
12 Oct 2025
@midischwarz12:libg.somidischwarz12 removed their profile picture.02:45:02
@midischwarz12:libg.somidischwarz12 set a profile picture.02:45:11
@anton:gersthof.comAnton (he/him) changed their display name from Anton to Anton (he/him).13:18:01
13 Oct 2025
@niklaskorz:matrix.orgniklaskorznvidia 535 update with beforementioned CVE fixes: https://github.com/NixOS/nixpkgs/pull/45161809:43:33
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/2621:54:56
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2025/q4/26 boringssl21:55:02

Show newer messages


Back to Room ListRoom Version: 6