!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

732 Members
Coordination and triage of security issues in nixpkgs227 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
29 Sep 2023
@hexa:lossy.networkhexaRedacted or Malformed Event01:47:08
@hexa:lossy.networkhexaRedacted or Malformed Event01:47:10
@openssl_rand:projectsegfau.lt@openssl_rand:projectsegfau.lt left the room.02:04:43
@hexa:lossy.networkhexa
In reply to @hexa:lossy.network
libvpx https://www.openwall.com/lists/oss-security/2023/09/28/5
fixed on master/release-23.05, will be part of the next channel bumps, but we still need to take care of all the vendored instances. effort similar to libwebp coordinated in #security-discuss:nixos.org
13:50:51
@lotte:chir.rs@lotte:chir.rs changed their profile picture.17:14:59
30 Sep 2023
@felschr:matrix.orgfelschr

https://github.com/NixOS/nixpkgs/pull/258137

https://github.com/NixOS/nixpkgs/pull/258138

05:28:11
@cafkafk:gitter.imcafkafk changed their profile picture.15:56:10
@hexa:lossy.networkhexa exim https://lwn.net/Articles/946004/ ajs124 21:54:28
@hexa:lossy.networkhexa

""Fixes are available in a protected repository and are ready to be applied by the distribution maintainers""

21:55:09
@hexa:lossy.networkhexa *

Fixes are available in a protected repository and are ready to be applied by the distribution maintainers

21:55:14
@hexa:lossy.networkhexa👏21:55:23
@tomberek:matrix.orgtombereki misread that as "exif" at first and thought, oh no.. here we go21:55:28
@hexa:lossy.networkhexahaha, please no more audio/vidoe/image format vulnerabilities this year 😄 21:55:46
* @raitobezarius:matrix.orgraitobezarius gets the libFuzzer out of the pocket and runs it on libcaca21:56:06
@hexa:lossy.networkhexa
In reply to @hexa:lossy.network
haha, please no more audio/vidoe/image format vulnerabilities this year 😄
https://github.com/NixOS/nixpkgs/pull/258295
23:16:55
1 Oct 2023
@vcunat:matrix.orgvcunat
In reply to @hexa:lossy.network
https://github.com/NixOS/nixpkgs/pull/258295
Wait, yet another libvpx CVE in a few days?
05:20:49
@vcunat:matrix.orgvcunat I mean, I'm in particular interested if the PR is urgent or could be staged instead, as doing those rebuilds again (on 2-3 branches) isn't cheap and it will slow down the staging-next* cycles - which also contain (milder) security fixes. 05:27:13
@vcunat:matrix.orgvcunat It is a different bug, but when public descriptions say only "crash", I can't tell severity at a glance (and no CVSS yet). 05:38:49
@vcunat:matrix.orgvcunatI really hate when importance is not stated and bug report links are private, so what one could do is only analyze the commit. Sure, no need to publish how to exploit it, but if you don't indicate severity...05:51:17
@vcunat:matrix.orgvcunatMaybe just wait, e.g. Firefox only released for the previous bug (VP8, not VP9 yet)05:57:31
@vcunat:matrix.orgvcunat *

Maybe just wait, e.g. Firefox only released for the previous bug (VP8, not VP9 yet)

EDIT: now I noticed the topic on #security-discuss:nixos.org but even there these questions aren't answered yet.

06:23:22
@errornointernet:envs.net@errornointernet:envs.net joined the room.08:32:35
@rwx-rwx-rwx:matrix.orgMikael Fangel joined the room.09:31:50
2 Oct 2023
@ajs124:ajs124.deajs124https://github.com/NixOS/nixpkgs/pull/258581 haven't tested much, but will do so now. if I don't draft it in the next hour or so, this can probably be merged.13:25:15
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.15:49:55
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.15:56:16
3 Oct 2023
@domenkozar:matrix.orgDomen Kožarhttps://twitter.com/bagder/status/170910392091452652514:14:43

Show newer messages


Back to Room ListRoom Version: 6