!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

717 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
18 Nov 2023
@ar:is-a.catari ❄ changed their display name from ar to ari ❄.16:09:04
@void68:matrix.orgvoidhttps://bugs.launchpad.net/hplip/+bug/203237517:39:49
@void68:matrix.orgvoidhplip17:39:51
@void68:matrix.orgvoidhttps://www.openwall.com/lists/oss-security/2023/11/17/117:40:16
@0x63af:matrix.org0x63af joined the room.21:14:54
19 Nov 2023
@pederbs:pvv.ntnu.nopbsds changed their display name from pbsds to pbsds (federation borken, may not see reply).03:36:12
@gwg313:matrix.orggwg313 joined the room.07:49:26
@zxgu:matrix.orgZXGU joined the room.10:56:53
@pederbs:pvv.ntnu.nopbsds changed their display name from pbsds (federation borken, may not see reply) to pbsds.20:39:12
21 Nov 2023
@bmgsh:matrix.orgbmgsh joined the room.09:01:17
@niksnut:matrix.orgniksnut changed their display name from niksnut to Eelco.16:37:26
22 Nov 2023
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (TZ: UTC-4) to Insurgo aka tlaurion (away).04:54:15
@aciceri:nixos.devaciceri joined the room.09:33:48
23 Nov 2023
@ThorHop:matrix.org@ThorHop:matrix.org joined the room.15:22:38
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (flaky frank) to hopland (evil entrepeneur).17:30:42
@ThorHop:matrix.org@ThorHop:matrix.org changed their display name from hopland (evil entrepeneur) to hopland (nixpkgs-rolling when).18:25:26
@felschr:matrix.orgfelschrhttps://github.com/NixOS/nixpkgs/pull/26916322:09:41
25 Nov 2023
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.13:21:49
@felschr:matrix.orgfelschrhttps://github.com/NixOS/nixpkgs/pull/269763 https://github.com/NixOS/nixpkgs/pull/26976413:32:45
@stigo:matrix.orgstigohttps://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038, i'm creating PRs for those18:20:26
@stigo:matrix.orgstigo * https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038, i'm creating PRs for those (affects perl538 and perl536)18:20:43
@stigo:matrix.orgstigo * https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)18:22:52
@stigo:matrix.orgstigo
In reply to @stigo:matrix.org
https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)
https://github.com/NixOS/nixpkgs/pull/269996
22:02:23
@stigo:matrix.orgstigo
In reply to @stigo:matrix.org
https://metacpan.org/release/PEVANS/perl-5.38.1/changes -Fixes CVE-2023-47038 and CVE-2023-47039, i'm creating PRs for those (affects perl538 and perl536)
* https://github.com/NixOS/nixpkgs/pull/269996 (currently targeted to master, let me know if you need it targeted to another branch)
22:03:16
@hexa:lossy.networkhexawill probably be a mass-rebuild, so unless this is an RCE I'd say we stage it 😄 22:07:11
@hexa:lossy.networkhexa

CVE-2023-47038 - Write past buffer end via illegal user-defined Unicode property

22:07:37
@hexa:lossy.networkhexaapparently limited to one-byte22:07:52
@hexa:lossy.networkhexa

CVE-2023-47039 - Perl for Windows binary hijacking vulnerability

22:07:57
@hexa:lossy.networkhexa🪟22:08:00
@hexa:lossy.networkhexa * 🪟s22:08:08

Show newer messages


Back to Room ListRoom Version: 6