!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

667 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22208 Servers

Load older messages


SenderMessageTime
15 Sep 2025
@kevincox:matrix.orgkevincox changed their display name from kevincox to kevincox (moved to @kevincox:kevincox.ca).19:40:13
16 Sep 2025
@teutat3s:pub.solarteutat3s https://github.com/NixOS/nixpkgs/pull/443455 | Fix CVE-2025-59161 / GHSA-m6c8-98f4-75rr "A malicious room can hide an unrelated room and cause it to be left when the malicious room is left " 14:41:53
@pyrox:pyrox.devdish [Fox/It/She]queued to merge, ty!16:06:25
@sandro:supersandro.deSandroShould we drop goldwarden if it's development is halted? https://github.com/quexten/goldwarden16:16:13
@hexa:lossy.networkhexa #security-discuss:nixos.org 16:18:47
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44357321:57:34
18 Sep 2025
@hexa:lossy.networkhexahttps://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2025-05.html12:47:05
19 Sep 2025
@mkg20001:mkg20001.iomkg20001 changed their profile picture.17:21:04
20 Sep 2025
@scr1bbles:matrix.org@scr1bbles:matrix.org left the room.15:40:33
21 Sep 2025
@hexa:lossy.networkhexahttps://paste.swordarmor.fr/raw/GvZ801:02:15
@hexa:lossy.networkhexa *
From: Maria Matejka via Bird-downstream <bird-downstream@lists.nic.cz>
To: BIRD downstream maintainers <bird-downstream@lists.nic.cz>
Cc: Maria Matejka <maria.matejka@nic.cz>
Reply-To: BIRD downstream maintainers <bird-downstream@lists.nic.cz>
Date: Fri, 19 Sep 2025 16:05:44 +0200
Subject: [Bird-downstream] Expected release of BIRD 3.0.5 and 3.1.4

[-- Attachment #1 --]
[-- Type: multipart/alternative, Encoding: 7bit, Size: 4.3K --]

Hello!

Please expect that hopefully on monday we're going to release fixup
versions 3.0.5 and 3.1.4; this time there is an embargoed patch included
so after we're done fixing, we're going to share the TGZs with you
privately before announcing and pushing to the public repository.

Please advise which timing is good for you to coordinate the release.
I would like to aim to monday evening or tuesday morning european time;
if something goes wrong, tuesday evening would be the time.

Thanks!
Maria

--
Maria Matejka (she/her) | BIRD Team Leader | CZ.NIC, z.s.p.o.

[-- Attachment #2 --]
[-- Type: text/plain, Encoding: 7bit, Size: 0.2K --]

_______________________________________________
Bird-downstream mailing list -- bird-downstream@lists.nic.cz
To unsubscribe send an email to bird-downstream-leave@lists.nic.cz
01:02:26
22 Sep 2025
@felix.schroeter:scs.ems.hostFelix Schröter changed their display name from Felix Schröter to Felix Schröter (🌄 29.09. – 05.10.).09:55:50
@hexa:lossy.networkhexahttps://trubka.network.cz/pipermail/bird-users/2025-September/018417.html21:38:56
@tom:dragar.deTomhttps://github.com/NixOS/nixpkgs/pull/44530322:29:47
@hexa:lossy.networkhexa https://seclists.org/oss-sec/2025/q3/177 Jan Tojnar 23:16:39
@hexa:lossy.networkhexa * https://seclists.org/oss-sec/2025/q3/177 webkitgtk Jan Tojnar 23:16:43
@hexa:lossy.networkhexaI'm a bit lost on webkitgtk versioning, we seem to be on 2.50.0 for all versions?23:17:48
23 Sep 2025
@vcunat:matrix.orgvcunat bird2 is NOT affected by these security issues, by the way. 05:33:14
@jtojnar:matrix.orgJan Tojnar yes. The versions in attribute name indicate ABI variant: 6_0 linked against GTK 4 and libsoup 3, 4_1 linked against GTK 3 and libsoup 3, 4_0 linked against GTK 3 and libsoup 2 (insecure) 09:27:13
@a-kenji:matrix.orgkenji changed their display name from a-kenji to kenji.10:38:47
24 Sep 2025
@lennart:0520.chlennartrelease notes are yet to be released, I guess that will open in the next 2-4 hours https://github.com/NixOS/nixpkgs/pull/44570905:28:45
@lennart:0520.chlennart* Zammad release notes are yet to be released, I guess that will open in the next 2-4 hours https://github.com/NixOS/nixpkgs/pull/44570905:28:51
@lennart:0520.chlennartthere is a fix to one security problem included, that I discovered. but they also had more disclosure processes involved in that release.05:33:13
@mtheil:scs.ems.hostMarkus Theil
OpenSSL Release Announcement

The OpenSSL project team would like to announce the upcoming release of
OpenSSL Library versions 3.5.4, 3.4.3, 3.3.5, 3.2.5 and 3.0.18.

We will also be releasing extended support for OpenSSL Library versions 1.0.2zm and 1.1.1zd, which will be available to premium support customers.

These releases will be made available on Tuesday, 30th September 2025, between 1300 and 1700 UTC.

These are security-fix releases. The highest severity issue fixed in each of these releases is Moderate:

https://openssl-library.org/policies/general/security-policy/index.html

Yours
The OpenSSL Project Team
07:27:04
@mtheil:scs.ems.hostMarkus TheilI'd like to skip 3.5.3 and directly bump to 3.5.4 and 3.0.18.07:27:56
@lennart:0520.chlennart
In reply to @lennart:0520.ch
Zammad release notes are yet to be released, I guess that will open in the next 2-4 hours https://github.com/NixOS/nixpkgs/pull/445709

three Security Advisories linkes

- https://zammad.com/en/advisories/zaa-2025-07
- https://zammad.com/en/advisories/zaa-2025-08
- https://zammad.com/en/advisories/zaa-2025-09

09:55:49
@lennart:0520.chlennart* three Security Advisories linked - https://zammad.com/en/advisories/zaa-2025-07 - https://zammad.com/en/advisories/zaa-2025-08 - https://zammad.com/en/advisories/zaa-2025-09 09:56:01
30 Sep 2025
@hexa:lossy.networkhexahttps://www.freeipa.org/release-notes/4-12-5.html16:03:10
@hexa:lossy.networkhexareleased a few hours ago16:04:56
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/44751216:06:54

Show newer messages


Back to Room ListRoom Version: 6