!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

652 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22202 Servers

Load older messages


SenderMessageTime
27 Aug 2025
@martijn:boers.emailmartijn joined the room.13:58:51
28 Aug 2025
@hexa:lossy.networkhexa https://github.com/storaged-project/udisks/security/advisories/GHSA-742q-gggc-473g udisks Jan Tojnar 20:55:32
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/08/28/1 https://www.openwall.com/lists/oss-security/2025/08/28/220:55:56
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/08/28/120:56:07
29 Aug 2025
@bluebirdlamentations:matrix.org@bluebirdlamentations:matrix.org left the room.16:13:53
@magic_rb:matrix.redalder.org@magic_rb:matrix.redalder.org changed their profile picture.19:27:40
30 Aug 2025
@tgerbet:matrix.orgtgerbet SigmaSquadron: https://xenbits.xen.org/xsa/advisory-471.html
Is this taken into account by the Xen team?
11:13:23
@sigmasquadron:matrix.orgSigmaSquadronuh I already fixed 471 I think11:40:39
@sigmasquadron:matrix.orgSigmaSquadronyeah that's the big one11:41:13
@sigmasquadron:matrix.orgSigmaSquadronwe just updated to the latest branch heads and then updated to 4.20.1 when it released11:41:36
@sigmasquadron:matrix.orgSigmaSquadronditto for 4.19.x on stable11:41:57
@sigmasquadron:matrix.orgSigmaSquadronYes, just confirmed that both 25.05 and 25.11 have all the patches for XSA 471.11:49:37
31 Aug 2025
@alper-celik:matrix.org@alper-celik:matrix.org left the room.16:00:07
1 Sep 2025
@lt1379:matrix.orgLun changed their display name from lun to Lun.15:55:15
2 Sep 2025
@aidalgol:tchncs.de@aidalgol:tchncs.de joined the room.21:55:24
3 Sep 2025
@ghpzin:envs.netghpzin joined the room.07:30:05
4 Sep 2025
@aidalgol:tchncs.de@aidalgol:tchncs.de changed their display name from Aidan Gauland to aidalgol[m].11:23:25
@aidalgol:tchncs.de@aidalgol:tchncs.de changed their display name from aidalgol[m] to aidalgol.11:24:11
5 Sep 2025
@cnorman:matrix.orgChris Norman set a profile picture.15:05:04
@cnorman:matrix.orgChris Norman changed their profile picture.15:05:17
6 Sep 2025
@ss:someonex.netSomeoneSerge (back on matrix) changed their display name from SomeoneSerge (Ever OOMed by Element) to SomeoneSerge (@nixcon & back on matrix).09:24:35
8 Sep 2025
@inayet:matrix.orgInayet set a profile picture.02:16:53
@stigo:matrix.orgstigohttps://github.com/NixOS/nixpkgs/pull/441228 CVE-2025-40928 and CVE-2025-4092915:32:42
9 Sep 2025
@sigmasquadron:matrix.orgSigmaSquadronXSAs #472 & #473: https://github.com/NixOS/nixpkgs/pull/441454 25.05: https://github.com/NixOS/nixpkgs/pull/44145513:02:56
@aciceri:nixos.devaciceri changed their display name from zrsk to aciceri.15:02:19
10 Sep 2025
@ss:someonex.netSomeoneSerge (back on matrix) changed their display name from SomeoneSerge (@nixcon & back on matrix) to SomeoneSerge (back on matrix).00:38:08
@hexa:lossy.networkhexahttps://kb.cert.org/vuls/id/461364 no new release yet, releases look like code drops02:17:22
@hexa:lossy.networkhexa* https://kb.cert.org/vuls/id/461364 no new release yet, releases look like code drops https://gitlab.com/hsleisink/hiawatha/-/commits/master?ref_type=HEADS02:17:32
@hexa:lossy.networkhexaonly maintainer was removed in 2019 and the package has been carried forth since by r-ryantm02:20:14
@hexa:lossy.networkhexa

Hiawatha is no longer actively supported by the developer, but the developer acknowledges the vulnerabilities and has included mitigations and remediations to all three vulnerabilities in the next release.

02:20:34

Show newer messages


Back to Room ListRoom Version: 6