!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

704 Members
Coordination and triage of security issues in nixpkgs217 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
26 Sep 2024
@qyliss:fairydust.spaceAlyssa Rosshttps://github.com/NixOS/nixpkgs/pull/34460108:26:33
@arianvp:matrix.orgArian joined the room.12:33:00
@arianvp:matrix.orgArianThis affects all nix versions. We need to make PRs for all the backports too no?12:34:17
@arianvp:matrix.orgArianNot just 2.24-specific afaics12:34:25
@emilazy:matrix.orgemily yes. looks like 2.18 is out, someone should open a PR. no other versions yet, waiting for Eelco to cut the tags I assume. (further discussion should probably go in #security-discuss:nixos.org) 12:35:40
@joerg:thalheim.ioMic92
In reply to @qyliss:fairydust.space

builtin:fetchurl: Enable TLS verification

I would argue the "information leak" should not affect many people. <nix/fetchurl.nix> is manly used by bootstrap tarballs.
18:48:48
@joerg:thalheim.ioMic92
In reply to @qyliss:fairydust.space

builtin:fetchurl: Enable TLS verification

* I would argue the "information leak" should not affect many people. <nix/fetchurl.nix> is manly used by bootstrap tarballs that do not suffer from this. So low impact for most people.
18:49:22
@hexa:lossy.networkhexa it probably doesn't, but that is for #security-discuss:nixos.org 18:52:36
@vcunat:matrix.orgvcunat
In reply to @fabianhjr:matrix.org
https://x.com/evilsocket/status/1838169889330135132

Claims 9.9 RCE unauthenticated over network affecting all GNU/Linux Systems
CUPS? Much earlier than expected, though:
https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
20:21:55
@fabianhjr:matrix.orgFabián Herediayeah, and also underwhelming for the original hype20:25:19
@void68:matrix.orgvoidI recall another one in hplip last year, somebody is getting efficient at it it seems.23:52:39
27 Sep 2024
@sigmasquadron:matrix.orgFernando Rodrigues joined the room.00:18:22
@vengmark2:matrix.org@vengmark2:matrix.org joined the room.02:26:49
@vengmark2:matrix.org@vengmark2:matrix.org left the room.02:29:26

Show newer messages


Back to Room ListRoom Version: 6