!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

721 Members
Coordination and triage of security issues in nixpkgs222 Servers

Load older messages


SenderMessageTime
9 Oct 2023
@lt1379:matrix.orgLunArch is using that patch https://gitlab.archlinux.org/archlinux/packaging/packages/libcue/-/commit/035bddf10ab0936e41daf829dac0ef3bd56bd2ce21:08:23
@lt1379:matrix.orgLunhttps://github.com/lipnitsk/libcue/commit/fdf72c8bded8d24cfa0608b8e97f2eed210a920e21:34:07
@k900:0upti.meK900Yay21:34:32
10 Oct 2023
@cafkafk:gitter.imcafkafk changed their display name from Christina Sørensen to cafkafk.03:39:01
@cafkafk:gitter.imcafkafk changed their profile picture.03:39:25
@k900:0upti.meK900New kernel updates with Xen DoS fix: https://github.com/NixOS/nixpkgs/pull/26029621:59:06
@sandro:supersandro.deSandro

CVE-2023-44487 7.5 score, 0-day, exploited in the wild

The fix (https://github.com/nghttp2/nghttp2/commit/72b4af6143681f528f1d237b21a9a7aee1738832) is probably not that easy to backport.

22:57:20
@sandro:supersandro.deSandroand we are quite a bit behind, there are changes that need attention and changing the package is a mass rebuild https://github.com/NixOS/nixpkgs/pull/21971222:57:58
@sandro:supersandro.deSandrohttps://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/ https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/22:58:45
11 Oct 2023
@vcunat:matrix.orgvcunatRebuild wouldn't be a problem now, as high-priority curl fix arrives today.05:59:05
@raitobezarius:matrix.orgraitobezariusIt's already out, see discussion channel05:59:19
@raitobezarius:matrix.orgraitobezariusRelease is not out yet05:59:23
@vcunat:matrix.orgvcunatEither way, 23.05 goes to rebuild first, and upgrading nghttp2 in there might not be great, so it would be nice if backport of this patch was easy.06:05:37
@leona:leona.isleonahttps://daniel.haxx.se/blog/2023/10/11/curl-8-4-0/06:08:35
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)https://github.com/curl/curl/releases/tag/curl-8_4_0 I'm on it06:14:49
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)Releases apparently aren't online yet. The links on https://curl.se/download.html return a 404.06:19:08
@raitobezarius:matrix.orgraitobezariusyep I advise to wait until they are out06:19:27
@raitobezarius:matrix.orgraitobezariuswe can theoretically apply the patch for 23.05 though06:19:55
@raitobezarius:matrix.orgraitobezariusi don't think we need to wait 8.4.0 for that06:20:00
@raitobezarius:matrix.orgraitobezariusor maybe we should bump 23.05 to 8.4.006:20:25
@raitobezarius:matrix.orgraitobezariusI don't know the policy here06:20:28
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)8.4.0 should be released soon™, I'd wait for the new release. 23.05 probably should get the backport as well due to this being a security issue06:22:17
@vcunat:matrix.orgvcunatWe're on 8.1.1 in 23.05.06:22:34
@vcunat:matrix.orgvcunatSo probably pick just the patches.06:22:45
@vcunat:matrix.orgvcunat * So probably pick just the patches in there. 06:23:07
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)Release is online, the darwin patch doesn't cleanly apply anymore. Someone with a darwin system needs to test whether my changes to the patch are good. 06:33:23
@vcunat:matrix.orgvcunatI can build on a slow x86_64-darwin.06:40:47
@vcunat:matrix.orgvcunatNo nixpkgs PR yet? (for staging-next-23.05)06:41:04
@vcunat:matrix.orgvcunatPatching is a pain here. Normally it would need addition of autoreconfHook, but that would cause nontrivial infinite recursion.06:42:31
@vcunat:matrix.orgvcunatAs for backporting itself, the conflicts didn't look bad at a glance.06:43:12

Show newer messages


Back to Room ListRoom Version: 6