!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

670 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

Load older messages


SenderMessageTime
13 Mar 2026
@tom:pub.solartom joined the room.07:28:33
@qyliss:fairydust.spaceAlyssa RossMerged into staging-nixos, and staging-nixos merge queued.08:20:21
@elvishjerricco:matrix.orgElvishJerriccocool, thank you08:21:27
@k900:0upti.meK900Probably want to also bonk the staging-next automerge08:26:09
@arianvp:matrix.orgArianShould we create a NixOS-specific advisory for this one? Given we're one of the few Distros in the bucket "new systemd version + machined by default"09:25:13
@emilazy:matrix.orgemilymaybe just post on the Discourse security announcements forum09:46:14
@arianvp:matrix.orgArianLmao redhat filed a CVE for it14:48:56
@arianvp:matrix.orgArianhttps://www.cve.org/CVERecord?id=CVE-2026-410514:49:11
@arianvp:matrix.orgArianAnd the CVE is wrong. Marks more things as affected than needed. Great. 14:49:40
@magic_rb:matrix.redalder.orgmagic_rbyou mean that rhel7 is not affected?14:53:34
@k900:0upti.meK900New kernels with apparmor security fixes: https://lore.kernel.org/stable/2026031357-statistic-surrogate-41a7@gregkh/T/#t16:46:35
@k900:0upti.meK900Someone please do the dance16:46:45
@ma27:nicht-so.sexyma27ok, on it.16:56:43
@arianvp:matrix.orgArian
In reply to @magic_rb:matrix.redalder.org
you mean that rhel7 is not affected?
Afaics not a single RHEL version is affected
17:36:21
@arianvp:matrix.orgArianRHEL is on 257. This vulnerability was introduced in 259. Idk wtf they're doing17:36:38
@magic_rb:matrix.redalder.orgmagic_rblmao17:37:31
14 Mar 2026
@amadaluzia:unredacted.orgamadaluzia -> 4d2.org changed their display name from amadaluzia to amadaluzia[uorg].18:50:59
@amadaluzia:4d2.orgamadaluzia joined the room.19:29:28
@amadaluzia:unredacted.orgamadaluzia -> 4d2.org changed their display name from amadaluzia[uorg] to amadaluzia -> 4d2.org.21:23:01

There are no newer messages yet.


Back to Room ListRoom Version: 6