!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

660 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
23 May 2025
@alisonjenkins:matrix.orgAlison Jenkins changed their profile picture.16:05:41
25 May 2025
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/05/23/215:50:31
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/05/23/2 ghostscript15:50:49
26 May 2025
@ximnoise:infosec.exchangeximnoise left the room.02:57:15
@ximnoise:infosec.exchangeximnoise joined the room.02:57:30
27 May 2025
@deeok:matrix.orgmatrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms) joined the room.07:49:31
@irenes:matrix.org@irenes:matrix.org left the room.09:00:51
@mdaniels5757:matrix.orgmdaniels5757 joined the room.23:45:31
28 May 2025
@numinit:matrix.orgMorgan (@numinit)

https://www.openwall.com/lists/oss-security/2025/05/28/4

https://curl.se/docs/CVE-2025-4947.html

curl (only wolfssl as a backend though)

05:53:27
@vcunat:matrix.orgvcunatThat seems to be only opt-in in nixpkgs. So a patch can be applied conditionally without any rebuild (and users of it will probably be rare here).06:03:22
@vcunat:matrix.orgvcunatMerged, but honestly I don't know what to do about stable nixpkgs.09:57:17
@emilazy:matrix.orgemilyseems backportable? is there anything breaking I'm missing?11:10:30
@zhaofeng:zhaofeng.liZhaofeng Li

Is the concern about the new features?

(not sure if replying in a thread will cause notifications - if so, let's move to #security-discuss:nixos.org )

15:42:37
29 May 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://github.com/NixOS/nixpkgs/issues/411881 so uh - do we pick commits into our jq? one of the two doesn't even have a fix commit, and i'd be surprised if the fix for the other actually applies properly...09:26:03
@k900:0upti.meK900What the lol09:26:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)jq had no release since 2023, but now the second 7.5+ cve09:27:21

Show newer messages


Back to Room ListRoom Version: 6