!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

709 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
30 Jan 2024
@vcunat:matrix.orgvcunatOne of these might be a low-rebuild change, but I suppose there's no hurry to get the changes anyway?15:43:08
@ajs124:ajs124.deajs1243.2 should be low rebuild15:45:19
@mtheil:scs.ems.host@mtheil:scs.ems.hostFor 23.11: https://github.com/NixOS/nixpkgs/pull/28502716:07:53
@delroth:delroth.netdelrothhttps://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt18:35:50
@delroth:delroth.netdelrothswitching the wrappers to musl was a very good idea18:36:06
@aloisw:kde.org@aloisw:kde.org
In reply to @delroth:delroth.net
switching the wrappers to musl was a very good idea
The wrappers do not call syslog.
18:53:01
@delroth:delroth.netdelroththis was a general statement on glibc, not on this particular vuln :)18:54:37
@tgerbet:matrix.orgtgerbet
In reply to @delroth:delroth.net
https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt
https://github.com/NixOS/nixpkgs/pull/285050
18:57:59
@delroth:delroth.netdelrothwe can move followup discussion to the discuss channel, I think we do need to remediate that last glibc vuln because wrappers forward all of argv (including argv[0]) to the wrapped program18:58:10
31 Jan 2024
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their profile picture.03:36:03
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their profile picture.06:21:40
@bytebandit:tac.lolDerivationDingus joined the room.09:35:10
@yuka:yuka.dev@yuka:yuka.dev joined the room.13:19:37
@delroth:delroth.netdelrothhttps://curl.se/docs/CVE-2024-0853.html (low sev)13:37:20
@hexa:lossy.networkhexataking that14:08:31
@shlevy:matrix.orgshlevy joined the room.14:55:05
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/28529515:19:05
1 Feb 2024
@deightz:matrix.orgdeightz joined the room.04:05:10
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/ TL;DR multiple container escapes in docker. runc, buildkit and containerd need to be updated. I'm on it07:50:44
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)Well, was already done by the bot, though the first two of these aren't merged yet https://github.com/NixOS/nixpkgs/pull/285438 https://github.com/NixOS/nixpkgs/pull/285407 https://github.com/NixOS/nixpkgs/pull/28541807:54:17
@leona:leona.isleonaI created some backport PRs to 23.11 (automatic wouldn't have worked): https://github.com/NixOS/nixpkgs/pull/285507 https://github.com/NixOS/nixpkgs/pull/285508 https://github.com/NixOS/nixpkgs/pull/28551009:34:13
@ximnoise:infosec.exchangeximnoise joined the room.09:53:02
@ximnoise:infosec.exchangeximnoise set a profile picture.10:03:31
@delroth:delroth.netdelrothhttps://mastodon.social/@MastodonEngineering/111856895554844910 the patches are out apparently15:22:11
@delroth:delroth.netdelrothhttps://github.com/mastodon/mastodon/releases/tag/v4.2.5 presumably15:22:28
@delroth:delroth.netdelrothand taken care of by https://github.com/NixOS/nixpkgs/pull/28555815:22:45
@schmittlauch:ohai.isschmittlauch (he/him) joined the room.16:55:14
@kudzu:envs.net@kudzu:envs.net left the room.17:45:38
2 Feb 2024
@shivayspec:matrix.orgSpecx joined the room.07:11:03
@daniel:routing.rocksdan_nrw joined the room.09:52:50

Show newer messages


Back to Room ListRoom Version: 6