!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

660 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

Load older messages


SenderMessageTime
20 Aug 2024
@a12l:matrix.org@a12l:matrix.org left the room.12:45:09
@teutat3s:pub.solarteutat3shttps://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-vhr5-g3pm-49fm https://github.com/NixOS/nixpkgs/pull/33605813:22:49
@emilazy:matrix.orgemily aha, knownVulnerabilities was just prescience! (taking a look and will merge after confirming aarch64-linux build) 13:46:07
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its) changed their display name from sophie to ⛧-440729 [sophie] (it/its).20:59:39
22 Aug 2024
@jaredbaur:matrix.orgJared Baur set a profile picture.02:07:15
@jassu:kumma.juttu.asiaJassukoPreviously semi-concerning FFmpeg CVEs seem to now have POC RCE published. Probably worth bumping the versions to the safe side rather soon. https://securityonline.info/cve-2024-7272-critical-heap-overflow-vulnerability-discovered-in-ffmpeg-poc-published/ CVE-2024-7272: Critical Heap Overflow Vulnerability Discovered in FFmpeg, PoC Published13:08:28
@hexa:lossy.networkhexa emily maybe? 13:09:29
@emilazy:matrix.orgemilyI think we have all the versions up to date13:36:10
@emilazy:matrix.orgemilyat least in staging 🫠13:36:14
@emilazy:matrix.orgemilyI'll check…13:36:24
@emilazy:matrix.orgemilyurgh this blogspam, where's the actual upstream announcement13:37:10
@emilazy:matrix.orgemilyokay so FFmpeg 4 is actually known vulnerable now??13:37:30
@jassu:kumma.juttu.asiaJassukoSorry, didn't find proper announcement, just the new releases on the release page: https://ffmpeg.org/download.html#releases13:38:59
@emilazy:matrix.orgemilyok, so https://github.com/NixOS/nixpkgs/pull/333021 is waiting for staging13:41:20
@emilazy:matrix.orgemilywe're on the latest 4 but the CVE says "A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5"13:41:31
@emilazy:matrix.orgemilyso there's no patch for 4?13:41:49
@emilazy:matrix.orgemily let's see if we can backport the commit. anyway, taking this to #security-discuss:nixos.org I guess 13:42:09
@niko:puppygock.gaynyanbinary 🏳️‍⚧️ left the room.17:19:37
@tgerbet:matrix.orgtgerbet networkException: https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html 20:53:38
@hexa:lossy.networkhexa networkException, emily 20:55:46
@hexa:lossy.networkhexabah, too slow20:56:00
@hexa:lossy.networkhexaexcuse me20:56:07
@networkexception:nwex.denetworkExceptionwe already have a build running20:56:21
@hexa:lossy.networkhexaenjoy20:56:30
24 Aug 2024
@cafkafk:gitter.imcafkafk changed their profile picture.07:02:16
@adbjesus:matrix.org@adbjesus:matrix.org left the room.15:53:46
25 Aug 2024
@r_i_s:matrix.orgris_ https://github.com/NixOS/nixpkgs/pull/274965 17:21:31
27 Aug 2024
@mtheil:scs.ems.hostMarkus Theil

New OpenSSL versions incoming in September. Fixes unclear.

The OpenSSL project team would like to announce the upcoming release of
OpenSSL versions 3.3.2, 3.2.3, 3.1.7 and 3.0.15.

These are security-fix releases. The highest severity issue fixed in
each of these four releases is Moderate:

https://openssl-library.org/policies/general/security-policy/

We will be also releasing extended support OpenSSL versions
1.1.1za and 1.0.2zk which will be available to premium support
customers.

These are also security-fix releases. The highest severity issue fixed
in each of these two releases is Low:

https://openssl-library.org/policies/general/security-policy/

These releases will be made available on Tuesday 3rd September 2024
between 1300-1700 UTC.


Yours
The OpenSSL Project Team
19:00:37
@r_i_s:matrix.orgris_lots of fun presents in the security review queue20:22:00
28 Aug 2024
@erictapen:chat.ccc-p.orgKerstin (she/her) changed their display name from kerstin to Kerstin (she/her).13:21:37

Show newer messages


Back to Room ListRoom Version: 6