!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

730 Members
Coordination and triage of security issues in nixpkgs222 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
15 Jul 2025
@ginkogruen:matrix.orgginkogruen joined the room.22:54:11
@cnorman:matrix.orgChris Norman joined the room.22:54:12
16 Jul 2025
@teutat3s:pub.solarteutat3shttps://github.com/electron/electron/releases/tag/v37.2.2 | Updated Chromium to 138.0.7204.100 https://github.com/NixOS/nixpkgs/pull/42575010:45:31
@teutat3s:pub.solarteutat3shttps://github.com/NLnetLabs/unbound/releases/tag/release-1.23.1 | fixes the Rebirthday Attack CVE-2025-599411:35:11
@hexa:lossy.networkhexaECS is disabled by default in nixpkgs11:38:48
@hexa:lossy.networkhexa* ECS is not compiled in by default in nixpkgs11:38:56
@me:indeednotjames.comemily25.05 is still vulnerable to the zero-day from 2025-06-30 for which electron released https://github.com/electron/electron/releases/tag/v37.2.0 on 2025-07-02. meaning electron_37 on 25.05 is affected by two different chromium zero-days. one zero-day that should have landed two weeks ago and another, the newer one, for which electron upstream no release yet. just to be clear, 138.0.7204.100, the release and PR you linked to, does not fix the newer zero-day from yesterday. this is a reoccurring pattern with electron in nixpkgs. do you want me to flag electron_37 on 25.05 as vulnerable until you find the time to fix the zero-day from two weeks ago?13:14:31
@winston:milli.ng@winston:milli.ng left the room.13:36:59
@leona:leona.isleonamatrix (servers+maybe clients) security update on 2025-07-22 https://matrix.org/blog/2025/07/security-predisclosure/16:16:40
@grimmauld:grapevine.grimmauld.deGrimmauld (migrated to @grimmauld:m.grimmauld.de) https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.5
More libxml2! YAY....
16:40:51
@lennart:0520.chlennart joined the room.17:23:22
@grimmauld:grapevine.grimmauld.deGrimmauld (migrated to @grimmauld:m.grimmauld.de)https://github.com/NixOS/nixpkgs/pull/425863 Fixes CVE-2025-49794, CVE-2025-49796, CVE-2025-49795, CVE-2025-6170 Four CVEs this time!!18:14:20
@grimmauld:grapevine.grimmauld.deGrimmauld (migrated to @grimmauld:m.grimmauld.de)* https://github.com/NixOS/nixpkgs/pull/425863 Fixes CVE-2025-49794, CVE-2025-49796, CVE-2025-49795, CVE-2025-6170 Four CVEs this time :)18:14:32

Show newer messages


Back to Room ListRoom Version: 6