| 25 May 2021 |
hexa | needs porting to both stable branches | 18:31:30 |
hexa |
A security issue in nginx resolver was identified, which might allow an attacker to cause 1-byte memory overwrite by using a specially crafted DNS response, resulting in worker process crash or, potentially, in arbitrary code execution (CVE-2021-23017).
| 18:31:53 |
hexa | https://security.googleblog.com/2021/05/introducing-half-double-new-hammering.html 😒 | 18:39:03 |
kevincox | You mean DRAM manufacturers didn't really fix the problem? surprised-pikachu | 18:48:07 |
hexa | https://github.com/NixOS/nixpkgs/pull/124433 | 22:20:58 |
hexa | please review | 22:21:07 |
hexa | thanks for the quick response everbody 🥳 | 22:40:09 |
| 26 May 2021 |
| samueldr changed their display name from samueldr to . | 00:46:03 |
| samueldr changed their display name from to samueldr. | 00:46:32 |
| Corbin joined the room. | 06:25:05 |
| niksnut joined the room. | 07:39:20 |
| Jonas Chevalier joined the room. | 11:02:40 |
| justinrestivo joined the room. | 12:27:51 |
| Arian joined the room. | 16:34:05 |
| re-ptarmigan❄️🐦️ joined the room. | 20:54:55 |
| samueldr changed their display name from samueldr to samueldr. | 21:05:24 |
| 27 May 2021 |
hexa | https://github.com/NixOS/nixpkgs/pull/124502 | 04:03:37 |
| cjbayliss (they/them) joined the room. | 04:31:42 |
| oida joined the room. | 10:49:56 |
| Fabian Affolter joined the room. | 18:03:03 |
dotlambda | On 20.09, libxml2 has at least 5 open CVEs: https://github.com/NixOS/nixpkgs/issues/124650. | 19:22:36 |
dotlambda | The patch for CVE-2021-3518 doesn't apply cleanly. | 19:22:46 |
hexa | awesome, the patches for curl 7.74.0 also don't apply cleanly. | 19:45:40 |
dotlambda | https://github.com/NixOS/nixpkgs/pull/124693 | 19:56:37 |
dotlambda | https://github.com/NixOS/nixpkgs/pull/124695 | 20:11:08 |
| 28 May 2021 |
| adisbladis left the room. | 00:39:13 |
| asymmetric joined the room. | 16:05:19 |
| 29 May 2021 |
hexa | https://github.com/NixOS/nixpkgs/pull/124839 | 02:28:02 |
hexa | found by moritz.hedtke | 02:28:19 |
| justinrestivo changed their display name from justinrestivo to oh caml >>=. | 12:20:58 |