!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

691 Members
Coordination and triage of security issues in nixpkgs216 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
23 May 2025
@stigo:matrix.orgstigoRed Hat CNA-LR responded yesterday that they will process the issues11:04:13
@mtheil:scs.ems.hostMarkus Theilhttps://openssl-library.org/news/vulnerabilities/#CVE-2025-457513:18:08
@mtheil:scs.ems.hostMarkus TheilI commented the CVE in https://github.com/NixOS/nixpkgs/pull/397123.13:19:24
@alisonjenkins:matrix.orgAlison Jenkins changed their profile picture.16:05:41
25 May 2025
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/05/23/215:50:31
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/05/23/2 ghostscript15:50:49
26 May 2025
@ximnoise:infosec.exchangeximnoise left the room.02:57:15
@ximnoise:infosec.exchangeximnoise joined the room.02:57:30
27 May 2025
@deeok:matrix.orgmatrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms) joined the room.07:49:31
@irenes:matrix.org@irenes:matrix.org left the room.09:00:51
@mdaniels5757:matrix.orgmdaniels5757 joined the room.23:45:31
28 May 2025
@numinit:matrix.orgMorgan (@numinit)

https://www.openwall.com/lists/oss-security/2025/05/28/4

https://curl.se/docs/CVE-2025-4947.html

curl (only wolfssl as a backend though)

05:53:27
@vcunat:matrix.orgvcunatThat seems to be only opt-in in nixpkgs. So a patch can be applied conditionally without any rebuild (and users of it will probably be rare here).06:03:22
@vcunat:matrix.orgvcunatMerged, but honestly I don't know what to do about stable nixpkgs.09:57:17
@emilazy:matrix.orgemilyseems backportable? is there anything breaking I'm missing?11:10:30
@zhaofeng:zhaofeng.liZhaofeng Li

Is the concern about the new features?

(not sure if replying in a thread will cause notifications - if so, let's move to #security-discuss:nixos.org )

15:42:37
29 May 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://github.com/NixOS/nixpkgs/issues/411881 so uh - do we pick commits into our jq? one of the two doesn't even have a fix commit, and i'd be surprised if the fix for the other actually applies properly...09:26:03
@k900:0upti.meK900What the lol09:26:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)jq had no release since 2023, but now the second 7.5+ cve09:27:21
@k900:0upti.meK900Has anyone rewritten it in rust yet09:27:37
@alisonjenkins:matrix.orgAlison Jenkinshttps://github.com/MiSawa/xq09:28:18
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) https://github.com/yamafaktory/jql
not sure how compatible it is though
also #security-discuss:nixos.org if we'll discuss that
09:28:34

Show newer messages


Back to Room ListRoom Version: 6