!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

734 Members
Coordination and triage of security issues in nixpkgs221 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
5 Oct 2023
@aloisw:kde.org@aloisw:kde.org joined the room.14:49:15
@rick:matrix.ciphernetics.nl@rick:matrix.ciphernetics.nl changed their display name from Rick (Mindavi) to Mindavi.15:31:36
6 Oct 2023
@pokon548:bukn.uk@pokon548:bukn.uk joined the room.07:37:44
@pokon548:bukn.uk@pokon548:bukn.uk left the room.10:35:05
@recoup3948:matrix.orgrecoup3948 joined the room.11:37:26
@hubofeverything:bark.lgbtHubble the Wolverine (they/them) joined the room.11:56:04
@Las:matrix.orgLas left the room.16:44:52
7 Oct 2023
@angelwn:matrix.organgelwn joined the room.12:45:07
@hubofeverything:bark.lgbtHubble the Wolverine (they/them) changed their display name from Hubble the Wolverine to Hubble the Wolverine (they/them).12:54:52
8 Oct 2023
@aleksana:mozilla.orgFind me at aleksana:qaq.li joined the room.06:52:56
@clefru:matrix.orgclefru joined the room.08:12:17
@realnyte:matrix.orgNyte joined the room.11:53:20
9 Oct 2023
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/25988100:48:34
@Challenged:matrix.orgChallenged joined the room.16:03:14
@k900:0upti.meK900https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/18:56:26
@k900:0upti.meK900Well shit18:56:27
@tgerbet:matrix.orgtgerbet
In reply to @k900:0upti.me
https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/
Opened https://github.com/NixOS/nixpkgs/pull/260052 for the sandbox escape
libcue patches do not seem available yet
19:25:33
@k900:0upti.meK900There's a patch on the blog post but I'm not sure if it's complete19:26:40
@lt1379:matrix.orgLun joined the room.21:07:10
@lt1379:matrix.orgLunArch is using that patch https://gitlab.archlinux.org/archlinux/packaging/packages/libcue/-/commit/035bddf10ab0936e41daf829dac0ef3bd56bd2ce21:08:23
@lt1379:matrix.orgLunhttps://github.com/lipnitsk/libcue/commit/fdf72c8bded8d24cfa0608b8e97f2eed210a920e21:34:07
@k900:0upti.meK900Yay21:34:32
10 Oct 2023
@cafkafk:gitter.imcafkafk changed their display name from Christina Sørensen to cafkafk.03:39:01
@cafkafk:gitter.imcafkafk changed their profile picture.03:39:25
@k900:0upti.meK900New kernel updates with Xen DoS fix: https://github.com/NixOS/nixpkgs/pull/26029621:59:06
@sandro:supersandro.deSandro

CVE-2023-44487 7.5 score, 0-day, exploited in the wild

The fix (https://github.com/nghttp2/nghttp2/commit/72b4af6143681f528f1d237b21a9a7aee1738832) is probably not that easy to backport.

22:57:20
@sandro:supersandro.deSandroand we are quite a bit behind, there are changes that need attention and changing the package is a mass rebuild https://github.com/NixOS/nixpkgs/pull/21971222:57:58
@sandro:supersandro.deSandrohttps://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/ https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/22:58:45
11 Oct 2023
@vcunat:matrix.orgvcunatRebuild wouldn't be a problem now, as high-priority curl fix arrives today.05:59:05
@raitobezarius:matrix.orgraitobezariusIt's already out, see discussion channel05:59:19

Show newer messages


Back to Room ListRoom Version: 6