!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

691 Members
Coordination and triage of security issues in nixpkgs215 Servers

Load older messages


SenderMessageTime
1 Jul 2024
@k900:0upti.meK900If no one snipes08:41:53
@k900:0upti.meK900
In reply to @emilazy:matrix.org
I'm building already & can do the PR but I don't know if there's specific procedure around assigning an advisory or whatever
No, just send it
08:41:57
@k900:0upti.meK900And mention the CVE in the description08:42:04
@emilazy:matrix.orgemilyalright, I'm on it08:42:17
@qyliss:fairydust.spaceAlyssa RossIs there even a CVE?08:42:52
@emilazy:matrix.orgemilyseems like there's not actually a CVE08:42:54
@qyliss:fairydust.spaceAlyssa Rossrelease notes don't mention one08:42:57
@emilazy:matrix.orgemilybut I'll mention it08:42:57
@qyliss:fairydust.spaceAlyssa Rossugh08:42:58
@emilazy:matrix.orgemilydid they even give any prior notice of this?08:44:09
@tgerbet:matrix.orgtgerbetNo it looks like it was reported by Qualys, they likely will publish an advisory later today I guess08:44:47
@ar:is-a.catari ❄gentoo patch mentions CVE-2024-6387 https://github.com/gentoo/gentoo/commit/083d7d12832b91073f5cac94df2ba067495857a708:45:41
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/32375308:45:45
@emilazy:matrix.orgemily
In reply to @ar:is-a.cat
gentoo patch mentions CVE-2024-6387 https://github.com/gentoo/gentoo/commit/083d7d12832b91073f5cac94df2ba067495857a7
thanks, I'll add that
08:45:55
@emilazy:matrix.orgemilycan someone check the build on linux if ofborg doesn't get to it first?08:48:18
@qyliss:fairydust.spaceAlyssa Rossalready on it08:48:23
@emilazy:matrix.orgemilydon't have my VM up right now08:48:24
@qyliss:fairydust.spaceAlyssa Ross23.11 is EOL as of yesterday btw08:48:25
@emilazy:matrix.orgemilyI figured we might as well throw people a bone when it's a root RCE08:48:43
@emilazy:matrix.orgemilyI was considering backporting to 23.05, even08:48:47
@qyliss:fairydust.spaceAlyssa Rossyeah fair enough08:48:49
@qyliss:fairydust.spaceAlyssa RossI've had RMs yell at me for backporting too far before, to avoid giving a false sense of security to users on ancient releases, so I wouldn't do 23.05.08:49:17
@qyliss:fairydust.spaceAlyssa Rossbut it's probably still 30 June somewhere in the world :P08:49:41
@emilazy:matrix.orgemilynot every day you get a bug this bad in a package this ubiquitous. but I'll let someone else decide to 23.05 if they feel like it then08:50:20
@tgerbet:matrix.orgtgerbet23.11 seems fair, 23.05 I would not bother08:51:34
@emilazy:matrix.orgemily macOS build is on checkPhase, can probably just merge when that finishes and the NixOS test passes 08:53:45
@emilazy:matrix.orgemilyyeah it finished08:53:50
@qyliss:fairydust.spaceAlyssa RossI'm 14 minutes into checkPhase on aarch64-linux08:54:21
@qyliss:fairydust.spaceAlyssa Ross* 14 minutes into the build08:54:42
@emilazy:matrix.orgemilydo we care about waiting for Gentoo's fix backport for stable or should we just do the major bump?08:56:03

Show newer messages


Back to Room ListRoom Version: 6