!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

686 Members
Coordination and triage of security issues in nixpkgs215 Servers

Load older messages


SenderMessageTime
16 Dec 2023
@hexa:lossy.networkhexaany plans for a 23.05 port of the fixes?01:41:48
@artturin:matrix.orgArtturin
In reply to @hexa:lossy.network
any plans for a 23.05 port of the fixes?
Cherry picking the commits to jq 1.6 has large conflicts and the code touched doesn't exist at all
01:47:55
@hexa:lossy.networkhexaso unlikely to be vulnerable?01:48:13
@artturin:matrix.orgArtturinPossibly but 1.6 is 5 years old so01:48:55
@artturin:matrix.orgArtturinThe code could exist in a very different form01:49:14
@lily:lily.flowersLily Foster
In reply to @hexa:lossy.network
so unlikely to be vulnerable?
The GHSA's both say first affected is 1.7
01:49:23
@hexa:lossy.networkhexaawesome!01:50:09
@r_i_s:matrix.orgris_hah jq author does first new release in years, 2 CVEs - that'll teach him!14:05:52
@phileas:asra.grsyd installs gentoo (they/them) joined the room.14:20:11
@phileas:asra.grsyd installs gentoo (they/them)FYI https://discourse.nixos.org/t/nixos-discourse-misconfigured-to-embed-external-img-src/3695614:20:39
@hexa:lossy.networkhexaforwarded to the admin team14:37:32
@phileas:asra.grsyd installs gentoo (they/them)
In reply to @hexa:lossy.network
forwarded to the admin team
thanks, have a nice weekend!
14:49:09
@r_i_s:matrix.orgris_https://github.com/NixOS/nixpkgs/pull/27164518:08:02
17 Dec 2023
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (away) to Insurgo aka tlaurion (Timezone: UTC-5).04:05:03
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (Timezone: UTC-5) to Insurgo aka tlaurion (TZ: UTC-5).04:05:11
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their profile picture.04:05:33
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their profile picture.04:06:02
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.04:39:22
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their profile picture.04:44:12
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their profile picture.04:46:28
@hexa:lossy.networkhexahttps://groups.google.com/g/golang-announce/c/-n5WqVC18LQ22:13:51
@hexa:lossy.networkhexarelease planned for tomorrow22:14:13
18 Dec 2023
@sandro:supersandro.deSandro That's an out of tree module, so patch-galore.... 13:01:55
@vengmark2:matrix.org@vengmark2:matrix.org joined the room.20:19:35
@vengmark2:matrix.org@vengmark2:matrix.org

Hi, I hope this is the appropriate channel to mention the Terrapin Attack. It seems the relevant paragraphs are these:

If you feel uncomfortable waiting for your SSH implementation to provide a patch, you can workaround this vulnerability by temporarily disabling the affected chacha20-poly1305@openssh.com and -etm@openssh.com MAC algorithms in the configuration of your SSH server (or client), and use unaffected algorithms like AES-GCM instead.

Fair word of warning: If configured improperly or your client does not support these algorithms, you may loose access to your server.

Maybe we could remove references to those algos?

20:28:17
@k900:0upti.meK900 #NixOS Security Discussion 20:29:41
@vengmark2:matrix.org@vengmark2:matrix.org left the room.20:31:20
19 Dec 2023
@jdemille:tchncs.deJulia DeMille joined the room.02:04:02
20 Dec 2023
@bb_wtt.jpeg:matrix.orgbb_wtt.jpeg joined the room.11:58:48
@julian:nekover.se@julian:nekover.se changed their display name from June to June 📞 5863.23:32:03

Show newer messages


Back to Room ListRoom Version: 6