!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

732 Members
Coordination and triage of security issues in nixpkgs220 Servers

Load older messages


SenderMessageTime
23 Nov 2023
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (flaky frank) to hopland (evil entrepeneur).17:30:42
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (evil entrepeneur) to hopland (nixpkgs-rolling when).18:25:26
@felschr:matrix.orgfelschrhttps://github.com/NixOS/nixpkgs/pull/26916322:09:41
25 Nov 2023
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.13:21:49
@felschr:matrix.orgfelschrhttps://github.com/NixOS/nixpkgs/pull/269763 https://github.com/NixOS/nixpkgs/pull/26976413:32:45
@stigo:matrix.orgstigohttps://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038, i'm creating PRs for those18:20:26
@stigo:matrix.orgstigo * https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038, i'm creating PRs for those (affects perl538 and perl536)18:20:43
@stigo:matrix.orgstigo * https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)18:22:52
@stigo:matrix.orgstigo
In reply to @stigo:matrix.org
https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)
https://github.com/NixOS/nixpkgs/pull/269996
22:02:23
@stigo:matrix.orgstigo
In reply to @stigo:matrix.org
https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)
* https://github.com/NixOS/nixpkgs/pull/269996 (currently targeted to master, let me know if you need it targeted to another branch)
22:03:16
@hexa:lossy.networkhexawill probably be a mass-rebuild, so unless this is an RCE I'd say we stage it 😄 22:07:11
@hexa:lossy.networkhexa

CVE-2023-47038 - Write past buffer end via illegal user-defined Unicode property

22:07:37
@hexa:lossy.networkhexaapparently limited to one-byte22:07:52
@hexa:lossy.networkhexa

CVE-2023-47039 - Perl for Windows binary hijacking vulnerability

22:07:57
@hexa:lossy.networkhexa🪟22:08:00
@hexa:lossy.networkhexa * 🪟s22:08:08
@stigo:matrix.orgstigo
In reply to @hexa:lossy.network
will probably be a mass-rebuild, so unless this is an RCE I'd say we stage it 😄
Done. (sigh sorry for the mass ping)
23:28:41
26 Nov 2023
@r_i_s:matrix.orgris_https://nvd.nist.gov/vuln/detail/CVE-2023-41419 and our gevent is really out of date00:20:13
@r_i_s:matrix.orgris_https://github.com/NixOS/nixpkgs/pull/27001900:39:08
@r_i_s:matrix.orgris_not sure what to do about 23.1100:41:05
@raitobezarius:matrix.orgraitobezariusimho backport00:41:32
@raitobezarius:matrix.orgraitobezariusthe issue seems quite problematic00:41:38
@raitobezarius:matrix.orgraitobezariusI mean, it would be nice to know about the blast radius though00:41:53
@r_i_s:matrix.orgris_ well, last change to gevent was 5001+ rebuilds 00:47:11
@r_i_s:matrix.orgris_guess we could either merge it to staging-next to find out how many breakages it causes or request a hydra job00:54:13
@r_i_s:matrix.orgris_will have a go at the patch in the morning00:58:28
@r_i_s:matrix.orgris_have done a lot of rebuilding with the above and haven't found any failures so far13:16:07
27 Nov 2023
@scm:sven.cc@scm:sven.cc joined the room.01:29:30
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (nixpkgs-rolling when) to hopland (valorent vicky).14:31:01
28 Nov 2023
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.org joined the room.03:17:52

Show newer messages


Back to Room ListRoom Version: 6