!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

724 Members
Coordination and triage of security issues in nixpkgs222 Servers

Load older messages


SenderMessageTime
13 Apr 2026
@haliliaj06jiroh:matrix.orgAndrei Jiroh [moved to @ajhalili2006:tchncs.de] changed their display name from Andrei Jiroh [moved to @ajhalili2006:envs.net] to Andrei Jiroh [moved to @ajhalili2006:tchncs.de].00:19:56
@sandro:supersandro.deSandro

https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.5

dotlambda

00:55:56
@hexa:lossy.networkhexahttps://github.com/dani-garcia/vaultwarden/releases/tag/1.35.601:03:50
@alesya-h:nixos.devAlesya changed their display name from Alesya Huzik to Alesya.01:46:22
@qweered_real:matrix.orgAliaksandr joined the room.02:28:46
@teutat3s:pub.solarteutat3shttps://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/6VW6OGVSC7LO3QUMBEZOPQFYYOFDJ452/12:18:31
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/50959014:52:33
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/50959114:52:40
@netali:cuties.devJenny joined the room.19:43:21
14 Apr 2026
@lukas:landgraf.moeLukas joined the room.01:53:47
@sandro:supersandro.deSandroTwo critical authentication bypasses https://github.com/oauth2-proxy/oauth2-proxy/releases/tag/v7.15.211:49:55
@sandro:supersandro.deSandrohttps://github.com/NixOS/nixpkgs/pull/50994112:02:50
@vcunat:matrix.orgvcunatX.Org Security Advisory: multiple security issues X.Org X server and Xwayland https://lists.x.org/archives/xorg-announce/2026-April/003677.html16:22:07
@klea:catgirl.cloudklea (she/her) joined the room.16:23:16
@klea:catgirl.cloudklea (she/her) changed their display name from klea to klea (she/her).16:27:22
@k900:0upti.meK900https://www.gamingonlinux.com/2026/04/x-org-x-server-and-xwayland-security-advisory-released-for-multiple-issues/17:41:07
@k900:0upti.meK900Oops17:41:09
15 Apr 2026
@vcunat:matrix.orgvcunat At a glance it's difficult for me to estimate how serious these are. (and thus if staging-next is worth the rebuild with the PR) 05:49:05
@kuflierl:matrix.orgkuflierl
In reply to @vcunat:matrix.org
At a glance it's difficult for me to estimate how serious these are. (and thus if staging-next is worth the rebuild with the PR)
From the descriptions alone I would say "CVE-2026-34001: XSYNC Use-after-free" is probably the most dangerous one since it could theoretically allow for local priv esc but that would need more work
08:08:15
@kuflierl:matrix.orgkuflierlRedacted or Malformed Event08:09:26
@kuflierl:matrix.orgkuflierl * i have not read the structs being freed, this is just me assuming there is a pointer somewhere in that strict 08:09:35
@kuflierl:matrix.orgkuflierl * i have not read the structs being freed, this is just me assuming there is a pointer somewhere in that strict 08:09:45
16 Apr 2026
@fgaz:matrix.orgfgaz Critical sandbox escape in luanti https://github.com/NixOS/nixpkgs/pull/510535 09:09:15
@k900:0upti.meK900Maybe just backport the fixed version? It's a videogame, do we really need to worry about breakage here09:10:55
@fgaz:matrix.orgfgazI don't know, I don't have time to review the breaking changes right now09:12:06
@fgaz:matrix.orgfgazkeep in mind it includes a game server as well. breaking changes might affect server operators09:12:44
@k900:0upti.meK900OK, going to merge for now09:12:44
@vcunat:matrix.orgvcunatHere's another case of dilemma between pulling breaking changes vs. marking as insecure: https://github.com/NixOS/nixpkgs/pull/50087611:50:14
@sandro:supersandro.deSandroJust build the package on hydra and then people can consume it without pain when allowing it.13:35:09
@hexa:lossy.networkhexahow about porting the patches?13:36:05

Show newer messages


Back to Room ListRoom Version: 6