!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

672 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22210 Servers

Load older messages


SenderMessageTime
23 Sep 2024
@k900:0upti.meK900Please don't16:36:43
@purpleseaotter:nope.chat@purpleseaotter:nope.chat
In reply to @k900:0upti.me
Please don't
Any reason? I wont but im a little confused
16:37:14
@k900:0upti.meK900Rewriting room history generally makes things more confusing16:37:40
@k900:0upti.meK900And people who follow the room have already been pinged and deleting your message won't unping them16:37:55
@purpleseaotter:nope.chat@purpleseaotter:nope.chat left the room.17:13:29
@fabianhjr:matrix.orgFabián Herediahttps://x.com/evilsocket/status/1838169889330135132 Claims 9.9 RCE unauthenticated over network affecting all GNU/Linux Systems18:02:39
@fabianhjr:matrix.orgFabián HerediaSays openwall disclosure coming on Sept 3018:06:13
@fabianhjr:matrix.orgFabián Herediahttps://x.com/evilsocket/status/183824160897996028518:06:17
@hexa:lossy.networkhexahttps://xcancel.com/evilsocket/status/183816988933013513218:08:36
@hexa:lossy.networkhexafull thread for those w/o twatteer18:08:41
@hexa:lossy.networkhexa * full thread for those w/o twatter18:08:44
@vcunat:matrix.orgvcunatNot sure. I read the thread that workarounds will be known on Oct 6, so I'm not sure how specific it will be on Sep 30.18:12:51
@emilazy:matrix.orgemilyopenwall presumably means the private distros list that we're not on18:13:19
@emilazy:matrix.orgemily this is a time it would be really nice to have a representative there even if we can't do secret Hydra builds 18:13:41
@hexa:lossy.networkhexa #security-discuss:nixos.org 18:14:03
@hexa:lossy.networkhexa ---\ 18:14:23
@hexa:lossy.networkhexa *
18:14:26
24 Sep 2024
@h7x4:nani.wtfh7x4 joined the room.11:07:21
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/344149 traefik fyi12:30:29
@ckie:ckie.devmei 🌒& changed their profile picture.23:19:32
26 Sep 2024
@fabianhjr:matrix.orgFabián Heredia set a profile picture.01:15:50
@qyliss:fairydust.spaceAlyssa Rosshttps://github.com/NixOS/nix/compare/2.24.7...2.24.808:11:54
@qyliss:fairydust.spaceAlyssa Ross

builtin:fetchurl: Enable TLS verification

08:12:22
@qyliss:fairydust.spaceAlyssa Ross

Ensure error messages don't leak private key

08:12:30
@qyliss:fairydust.spaceAlyssa Rosshttps://github.com/NixOS/nixpkgs/pull/34460108:26:33
@arianvp:matrix.orgArian joined the room.12:33:00
@arianvp:matrix.orgArianThis affects all nix versions. We need to make PRs for all the backports too no?12:34:17
@arianvp:matrix.orgArianNot just 2.24-specific afaics12:34:25
@emilazy:matrix.orgemily yes. looks like 2.18 is out, someone should open a PR. no other versions yet, waiting for Eelco to cut the tags I assume. (further discussion should probably go in #security-discuss:nixos.org) 12:35:40
@joerg:thalheim.ioMic92
In reply to @qyliss:fairydust.space

builtin:fetchurl: Enable TLS verification

I would argue the "information leak" should not affect many people. <nix/fetchurl.nix> is manly used by bootstrap tarballs.
18:48:48

Show newer messages


Back to Room ListRoom Version: 6