!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

736 Members
Coordination and triage of security issues in nixpkgs226 Servers

Load older messages


SenderMessageTime
30 Sep 2023
@hexa:lossy.networkhexahaha, please no more audio/vidoe/image format vulnerabilities this year 😄 21:55:46
* @raitobezarius:matrix.orgraitobezarius gets the libFuzzer out of the pocket and runs it on libcaca21:56:06
@hexa:lossy.networkhexa
In reply to @hexa:lossy.network
haha, please no more audio/vidoe/image format vulnerabilities this year 😄
https://github.com/NixOS/nixpkgs/pull/258295
23:16:55
1 Oct 2023
@vcunat:matrix.orgvcunat
In reply to @hexa:lossy.network
https://github.com/NixOS/nixpkgs/pull/258295
Wait, yet another libvpx CVE in a few days?
05:20:49
@vcunat:matrix.orgvcunat I mean, I'm in particular interested if the PR is urgent or could be staged instead, as doing those rebuilds again (on 2-3 branches) isn't cheap and it will slow down the staging-next* cycles - which also contain (milder) security fixes. 05:27:13
@vcunat:matrix.orgvcunat It is a different bug, but when public descriptions say only "crash", I can't tell severity at a glance (and no CVSS yet). 05:38:49
@vcunat:matrix.orgvcunatI really hate when importance is not stated and bug report links are private, so what one could do is only analyze the commit. Sure, no need to publish how to exploit it, but if you don't indicate severity...05:51:17
@vcunat:matrix.orgvcunatMaybe just wait, e.g. Firefox only released for the previous bug (VP8, not VP9 yet)05:57:31
@vcunat:matrix.orgvcunat *

Maybe just wait, e.g. Firefox only released for the previous bug (VP8, not VP9 yet)

EDIT: now I noticed the topic on #security-discuss:nixos.org but even there these questions aren't answered yet.

06:23:22
@errornointernet:envs.net@errornointernet:envs.net joined the room.08:32:35
@rwx-rwx-rwx:matrix.orgMikael Fangel joined the room.09:31:50
2 Oct 2023
@ajs124:ajs124.deajs124https://github.com/NixOS/nixpkgs/pull/258581 haven't tested much, but will do so now. if I don't draft it in the next hour or so, this can probably be merged.13:25:15
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.15:49:55
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.15:56:16
3 Oct 2023
@domenkozar:matrix.orgDomen Kožarhttps://twitter.com/bagder/status/170910392091452652514:14:43
@raitobezarius:matrix.orgraitobezarius

pretty much, yes. But this time actually the worst security problem found in curl in a long time.

14:15:06
@raitobezarius:matrix.orgraitobezarius(hope it's not my code)14:15:14
@delroth:delroth.netdelroth cc vcunat - we should figure out a staging-next timeline that works well with this (libcurl patch dropping on Oct 11) 14:59:17
@delroth:delroth.netdelrothdunno if we should extend the current staging-next cycle or make a short next cycle14:59:42
@vcunat:matrix.orgvcunatcurl is mainly a problem because of rebuilding darwin stdenvs. Not that much otherwise IIRC.15:00:09
@vcunat:matrix.orgvcunatOur farm has constant amount of darwin. (almost all aarch64+rosetta)15:01:20
@delroth:delroth.netdelrothhttps://github.com/NixOS/nixpkgs/pull/244468 5001+ Linux too apparently (let's maybe switch this discussion to the other channel)15:01:58
@vcunat:matrix.orgvcunat * curl is mainly a problem because of rebuilding darwin stdenvs. Not that much otherwise IIRC. EDIT: I was wrong, probably, looks big on linux, too.15:15:40
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (AFK) to Insurgo aka tlaurion (TZ: UTC-4).23:41:16
4 Oct 2023
@hexa:lossy.networkhexahttps://lists.x.org/archives/xorg/2023-October/061506.html01:24:04
@hexa:lossy.networkhexano idea who to tag tbh01:24:43
@raitobezarius:matrix.orgraitobezarius cc K900 ⚡️ Jan Tojnar and NickCao who touched this stuff last time AFAIK 01:26:23
@artturin:matrix.orgArtturin
In reply to @hexa:lossy.network
https://lists.x.org/archives/xorg/2023-October/061506.html
https://github.com/NixOS/nixpkgs/pull/258841
02:18:35
@k900:0upti.meK900Wait me05:56:46
@k900:0upti.meK900When did I touch Xorg stuff05:56:56

Show newer messages


Back to Room ListRoom Version: 6