!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

683 Members
Coordination and triage of security issues in nixpkgs211 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
17 Jun 2025
@hexa:lossy.networkhexahttps://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx unmaintained 😕 22:02:13
@hexa:lossy.networkhexa* https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx unmaintained in nixpkgs 😕 22:02:17
@hexa:lossy.networkhexa

Systems are vulnerable if they use pam_namespace to polyinstantiate a directory

22:02:49
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2025/06/17/5 libblockdev/udisks Jan Tojnar 22:06:45
18 Jun 2025
@jtojnar:matrix.orgJan Tojnarthanks, opened https://github.com/NixOS/nixpkgs/pull/41776307:20:55
@leona:leona.isleonacan look in around 8 hours if no one beats me to that07:51:03
@h0nig2k:matrix.orgh0nig2khttps://github.com/NixOS/nixpkgs/pull/417898 for CVE-2025-46727 (please backport to 25.05 as well, thank you)15:52:17
@vcunat:matrix.orgvcunat

updated X too soon

A fix will be issued in xorg-server-21.1.18 and xwayland-24.1.8 shortly.

https://lists.x.org/archives/xorg-announce/2025-June/003611.html

16:08:45
@hexa:lossy.networkhexaRedacted or Malformed Event16:23:13
@hexa:lossy.networkhexaRedacted or Malformed Event16:23:39
@hexa:lossy.networkhexaRedacted or Malformed Event16:23:49
@aleksana:mozilla.orgFind me at aleksana:qaq.li
In reply to @jtojnar:matrix.org
thanks, opened https://github.com/NixOS/nixpkgs/pull/417763
This hasn't been backported to 24.11 because of merge conflict, have we abandoned 24.11 yet?
17:18:10
@hexa:lossy.networkhexanot yet17:19:56
@vcunat:matrix.orgvcunatEnd of the month is promised traditionally.17:24:14
20 Jun 2025
@alina:kescher.at@alina:kescher.at changed their display name from alina, dognitohazard 🏳️‍⚧️🐾 to alina, moved to @alina:catgirl.cloud.18:14:34

Show newer messages


Back to Room ListRoom Version: 6