!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

713 Members
Coordination and triage of security issues in nixpkgs220 Servers

Load older messages


SenderMessageTime
25 Nov 2023
@stigo:matrix.orgstigo
In reply to @stigo:matrix.org
https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)
https://github.com/NixOS/nixpkgs/pull/269996
22:02:23
@stigo:matrix.orgstigo
In reply to @stigo:matrix.org
https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)
* https://github.com/NixOS/nixpkgs/pull/269996 (currently targeted to master, let me know if you need it targeted to another branch)
22:03:16
@hexa:lossy.networkhexawill probably be a mass-rebuild, so unless this is an RCE I'd say we stage it 😄 22:07:11
@hexa:lossy.networkhexa

CVE-2023-47038 - Write past buffer end via illegal user-defined Unicode property

22:07:37
@hexa:lossy.networkhexaapparently limited to one-byte22:07:52
@hexa:lossy.networkhexa

CVE-2023-47039 - Perl for Windows binary hijacking vulnerability

22:07:57
@hexa:lossy.networkhexa🪟22:08:00
@hexa:lossy.networkhexa * 🪟s22:08:08
@stigo:matrix.orgstigo
In reply to @hexa:lossy.network
will probably be a mass-rebuild, so unless this is an RCE I'd say we stage it 😄
Done. (sigh sorry for the mass ping)
23:28:41
26 Nov 2023
@r_i_s:matrix.orgris_https://nvd.nist.gov/vuln/detail/CVE-2023-41419 and our gevent is really out of date00:20:13
@r_i_s:matrix.orgris_https://github.com/NixOS/nixpkgs/pull/27001900:39:08
@r_i_s:matrix.orgris_not sure what to do about 23.1100:41:05
@raitobezarius:matrix.orgraitobezariusimho backport00:41:32
@raitobezarius:matrix.orgraitobezariusthe issue seems quite problematic00:41:38
@raitobezarius:matrix.orgraitobezariusI mean, it would be nice to know about the blast radius though00:41:53
@r_i_s:matrix.orgris_ well, last change to gevent was 5001+ rebuilds 00:47:11
@r_i_s:matrix.orgris_guess we could either merge it to staging-next to find out how many breakages it causes or request a hydra job00:54:13
@r_i_s:matrix.orgris_will have a go at the patch in the morning00:58:28
@r_i_s:matrix.orgris_have done a lot of rebuilding with the above and haven't found any failures so far13:16:07
27 Nov 2023
@scm:sven.cc@scm:sven.cc joined the room.01:29:30
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (nixpkgs-rolling when) to hopland (valorent vicky).14:31:01
28 Nov 2023
@a-n-n-a-l-e-e:matrix.org@a-n-n-a-l-e-e:matrix.org joined the room.03:17:52
@hexa:lossy.networkhexahttps://forgejo.org/2023-11-release-v1-20-5-1/12:06:24
@hexa:lossy.networkhexamaster on 1.21.1-0, release-23.11 on 1.20.5-1, release-23.05 on 1.19.4-012:07:48
@hexa:lossy.networkhexaonly worried about release-23.05 here12:08:17
@hexa:lossy.networkhexahttps://github.com/go-gitea/gitea/releases/tag/v1.20.6 master and release-23.11 on 1.20.5, release-23.05 on 1.19.412:27:27
@hexa:lossy.networkhexa ma27: for gitea 12:28:56
@ma27:nicht-so.sexyma27will try to take a look today13:21:00
@me:indeednotjames.comemily
In reply to @hexa:lossy.network
only worried about release-23.05 here

All versions back to gogs are affected (depending on the endpoint)

source: https://matrix.to/#/!qjPHwFPdxhpLkXMkyP:matrix.org/$ONM9CMUFMAnJjhtvbaStCoYoWS2lkazKxgfsDjwQzg4?via=matrix.org&via=tchncs.de

18:04:55
29 Nov 2023
@julienmalka:matrix.orgJulienhttps://jellyfin.org/posts/jellyfin-security-and-you/13:11:29

Show newer messages


Back to Room ListRoom Version: 6