!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

652 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22202 Servers

Load older messages


SenderMessageTime
10 Oct 2025
@leona:leona.isleona* found a not maintained TLS impl version (mbedtls_2), marked as vulnerable for now: https://github.com/NixOS/nixpkgs/pull/45068814:26:09
@niklaskorz:matrix.orgniklaskorzhttps://github.com/NixOS/nixpkgs/pull/45072916:48:13
11 Oct 2025
@midischwarz12:libg.somidischwarz12 joined the room.21:01:41
12 Oct 2025
@midischwarz12:libg.somidischwarz12 removed their profile picture.02:45:02
@midischwarz12:libg.somidischwarz12 set a profile picture.02:45:11
@anton:gersthof.comAnton (he/him) changed their display name from Anton to Anton (he/him).13:18:01
13 Oct 2025
@niklaskorz:matrix.orgniklaskorznvidia 535 update with beforementioned CVE fixes: https://github.com/NixOS/nixpkgs/pull/45161809:43:33
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/2621:54:56
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2025/q4/26 boringssl21:55:02
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/27 poppler21:55:17
@hexa:lossy.networkhexarequires poppler-25.10.022:27:01
@hexa:lossy.networkhexa * requires poppler-25.10.0 (Jan Tojnar) 22:27:09
@hexa:lossy.networkhexahttps://gitlab.freedesktop.org/poppler/poppler/-/commit/4ce27cc826bf90cc8dbbd8a8c87bd913cccd7ec022:27:29
@hexa:lossy.networkhexahttps://webkitgtk.org/security/WSA-2025-0007.html webkitgtk23:11:01
14 Oct 2025
@vcunat:matrix.orgvcunatThe boringssl thread doesn't seem very convincing, i.e. no claim is made that the leak goes beyond key length and similar "uninteresting" parameters.08:56:06
@vcunat:matrix.orgvcunatAll crypto libs will take longer time when using longer keys, I believe. (up to some exceptions maybe when the difference in length is small)08:57:39
@jassu:kumma.juttu.asiaJassukoBeing able to reduce the search space to a specific amount of bits for the private key is a way more information than you might expect. EC priv key is practically a number between 1 and N-1, where N is the order of the curve. For example with P-256 curve you can have a private key that has 253 effective bits in its representation. Knowing this would directly allow you to limit your search space for figuring out the private key to under 1/8 of the full key space. The practical implications as of now probably don't warrant any direct panic or actions, but building cryptography things is generally based on a strict set of design goals and delivering 100% of the promises given, so in that sense this is a timing side channel which can reveal few bits worth of information of the private key whenever an oracle exists that allows the repeated timing measurements. Well worth fixing and updating, even though there would not be need for a panic-mode actions at this point. Besides, all kinds of weakenings left unpatched tend to gather up, and then the day comes when your security gets broken because someone figured a way to use those things together in clever ways.14:57:17
@vcunat:matrix.orgvcunatI don't think that's what the post implied.14:59:02
@vcunat:matrix.orgvcunat(but it was short)14:59:13
@vcunat:matrix.orgvcunat* (but it was short and didn't go into details)14:59:20
@vcunat:matrix.orgvcunatReducing search space to 1/8th is unpleasant but not a security risk.14:59:56
@vcunat:matrix.orgvcunat* Either way, reducing search space to 1/8th is unpleasant but not a security risk.15:00:03
@vcunat:matrix.orgvcunatI can buy 8-times more powerful computer easily.15:00:23
@jassu:kumma.juttu.asiaJassukoThe test vectors in the git was a bunch of private keys that has different amounts of effective bits in them. I'd say this is probably the relevant context of the thing.15:00:39
@vcunat:matrix.orgvcunat Let's move this to #security-discuss:nixos.org though. 15:00:52
@phale:matrix.orgPhil Hale joined the room.16:26:17
@jtojnar:matrix.orgJan Tojnarhttps://github.com/NixOS/nixpkgs/pull/45121516:34:18
@pinpox:matrix.orgpinpox changed their display name from pinpox to reaktor.21:14:03
@pinpox:matrix.orgpinpox changed their display name from reaktor to pinpox.21:14:04
@jtojnar:matrix.orgJan Tojnarhttps://github.com/NixOS/nixpkgs/pull/452081 21:56:15

Show newer messages


Back to Room ListRoom Version: 6