!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

714 Members
Coordination and triage of security issues in nixpkgs218 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
23 Oct 2023
@ss:someonex.netSomeoneSerge (matrix works sometimes) changed their display name from Someone (UTC+3) to SomeoneSerge (UTC+1).09:09:21
@robin.gloster:matrix.mayflower.deglobin left the room.09:49:04
@globin:toznenetl.chatglobin set a profile picture.14:27:40
24 Oct 2023
@hexa:lossy.networkhexaworking on openssl14:03:43
@hexa:lossy.networkhexa

Mitigate incorrect resize handling for symmetric cipher keys and IVs. (CVE-2023-5363)

14:07:36
@hexa:lossy.networkhexahttps://github.com/openssl/openssl/blob/openssl-3.0.12/NEWS.md#major-changes-between-openssl-3011-and-openssl-3012-24-oct-202314:07:41
@k900:0upti.meK900That doesn't look too bad at least14:08:04
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/26315014:14:26
@hexa:lossy.networkhexa

Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() with OSSL_PARAM parameters that alter the key or IV length (CVE-2023-5363).

14:20:20
@hexa:lossy.networkhexanow with more words!14:20:24
@mtheil:scs.ems.host@mtheil:scs.ems.host hexa: Do you also open a PR for 23.05 or can I? 14:43:56
@hexa:lossy.networkhexahrm, backport action won't do it, because of openssl_3_114:44:53
@mtheil:scs.ems.host@mtheil:scs.ems.hostyep14:44:58
@hexa:lossy.networkhexamake sure to cherry-pick with -x14:45:08
@hexa:lossy.networkhexaand make sure to change hash back to sha25614:45:22
@hexa:lossy.networkhexawe're not in a hurry really, because staging-next will likely go first14:46:55

Show newer messages


Back to Room ListRoom Version: 6