| 23 Oct 2023 |
| globin set a profile picture. | 14:27:40 |
| 24 Oct 2023 |
hexa | working on openssl | 14:03:43 |
hexa |
Mitigate incorrect resize handling for symmetric cipher keys and IVs. (CVE-2023-5363)
| 14:07:36 |
hexa | https://github.com/openssl/openssl/blob/openssl-3.0.12/NEWS.md#major-changes-between-openssl-3011-and-openssl-3012-24-oct-2023 | 14:07:41 |
K900 | That doesn't look too bad at least | 14:08:04 |
hexa | https://github.com/NixOS/nixpkgs/pull/263150 | 14:14:26 |
hexa |
Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() with OSSL_PARAM parameters that alter the key or IV length (CVE-2023-5363).
| 14:20:20 |
hexa | now with more words! | 14:20:24 |
@mtheil:scs.ems.host | hexa: Do you also open a PR for 23.05 or can I? | 14:43:56 |
hexa | hrm, backport action won't do it, because of openssl_3_1 | 14:44:53 |
@mtheil:scs.ems.host | yep | 14:44:58 |
hexa | make sure to cherry-pick with -x | 14:45:08 |
hexa | and make sure to change hash back to sha256 | 14:45:22 |
hexa | we're not in a hurry really, because staging-next will likely go first | 14:46:55 |
@mtheil:scs.ems.host | ok | 14:51:42 |
hexa | and if the version that goes into staging changes, you'll need to update the reference 😛 | 14:55:06 |
@mtheil:scs.ems.host | Sry, overlooked the target branch :( | 14:56:09 |
@mtheil:scs.ems.host | In reply to @hexa:lossy.network and if the version that goes into staging changes, you'll need to update the reference 😛 I'll wait for it. Thanks for the fast close 😅 | 14:59:19 |
| 25 Oct 2023 |
| @federicodschonborn:matrix.org changed their profile picture. | 00:13:15 |
K900 | https://github.com/NixOS/nixpkgs/pull/263317 kernel update with a potentially pretty spooky KVM vuln | 11:07:42 |
K900 | https://www.phoronix.com/news/X.Org-Halloween-Bugs-2023 and a bunch of X11 vulns because duh | 11:19:48 |
K900 | @Artturin what's the status on the X11 untangling PR? | 11:20:09 |
Artturin | In reply to @k900:0upti.me https://www.phoronix.com/news/X.Org-Halloween-Bugs-2023 and a bunch of X11 vulns because duh Haven't started manual moving so just update like normal | 17:26:58 |
| 26 Oct 2023 |
| @lotte:chir.rs changed their profile picture. | 06:50:34 |
felschr | https://github.com/NixOS/nixpkgs/pull/263399
https://github.com/NixOS/nixpkgs/pull/263401 | 12:17:26 |
| streets joined the room. | 12:33:50 |
felschr | PRs now have one approval each | 21:44:21 |
| 27 Oct 2023 |
| @federicodschonborn:matrix.org changed their profile picture. | 01:24:45 |
vcunat | In reply to @k900:0upti.me https://www.phoronix.com/news/X.Org-Halloween-Bugs-2023 and a bunch of X11 vulns because duh I wonder how bad they are - rebuilds vs. speed of update: https://github.com/NixOS/nixpkgs/pull/263689#issuecomment-1782340466 | 06:15:31 |
K900 | Huh | 06:16:41 |