!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

723 Members
Coordination and triage of security issues in nixpkgs219 Servers

Load older messages


SenderMessageTime
11 Oct 2023
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its) * PR for staging-23.05: https://github.com/NixOS/nixpkgs/pull/260381 06:50:19
@vcunat:matrix.orgvcunatHmm, that's annoying. It seems really hard to resolve autoconf issues without reimporting nixpkgs. I tested the patch by using autoreconfHook from a different nixpkgs version. With that the build passes with the backported patch.07:44:38
@vcunat:matrix.orgvcunatI don't know, I'll probably give it up for the current staging-next-23.05. In case someone wants to experiment, you can get prototype patch for nghttp2 (version without touching generated stuff): https://github.com/vcunat/nghttp2/pull/new/p/backport-cve-2023-4448710:21:12
@dexternemrod:matrix.org@dexternemrod:matrix.org left the room.17:47:38
@xfix:matrix.org@xfix:matrix.org changed their display name from xfix to xfix (she/her).18:19:58
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.19:34:58
@obfusk:matrix.org幸猫 (𝗍𝗁𝖾𝗒/𝗍𝗁𝖾𝗆) changed their display name from FC (they/them) to Fay (she/her).20:54:19
12 Oct 2023
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)Can someone please review and merge the PR for curl 8.4.0? https://github.com/NixOS/nixpkgs/pull/26037806:42:30
@ajs124:ajs124.deajs124 changed their profile picture.21:42:48
13 Oct 2023
@akechishiro:matrix.orgAkechiShiroRedacted or Malformed Event15:21:14
@akechishiro:matrix.orgAkechiShiroHere is an oss-security mail that has a lot of advisory compiled in : https://www.openwall.com/lists/oss-security/2023/10/10/615:22:24
@akechishiro:matrix.orgAkechiShiro * Here is an oss-security mail that has a lot of advisory compiled in (so we have a better idea which software needs an update or not) : https://www.openwall.com/lists/oss-security/2023/10/10/6 15:22:41
@akechishiro:matrix.orgAkechiShiroI see even more links here : https://www.cve.org/CVERecord?id=CVE-2023-44487 But some are not strictly about open source software, might also be of help16:09:38
14 Oct 2023
@leifb:matrix.orgleifb joined the room.09:22:09
15 Oct 2023
@meetmangukiya:matrix.orgmeet changed their display name from meet to meetm.07:05:59
@thefossguy:matrix.orgPratham Patel changed their display name from Pratham Patel to Pratham Patel (you can mention me).07:24:16
@k900:0upti.meK900https://exim.org/static/doc/security/CVE-2023-zdi.txt20:35:06
@k900:0upti.meK900Five billion CVEs in exim20:35:12
@hexa:lossy.networkhexa ajs124: 20:40:26
@hexa:lossy.networkhexapretty sure these aren't new20:40:40
@k900:0upti.meK900Some aren't20:41:51
@k900:0upti.meK900But there's some bonus new ones20:41:54
@ajs124:ajs124.deajs124
In reply to @hexa:lossy.network
pretty sure these aren't new
they aren't, but the fixes are new https://github.com/NixOS/nixpkgs/pull/261279
21:07:31
17 Oct 2023
@camocatx:matrix.orgcamocatx joined the room.21:51:51
18 Oct 2023
@sptz:matrix.org@sptz:matrix.org joined the room.06:01:15
@mtheil:scs.ems.host@mtheil:scs.ems.host
The OpenSSL project team would like to announce the upcoming release of
OpenSSL versions 3.1.4 and 3.0.12.

These releases will be made available on Tuesday 24th October 2023
between 1300-1700 UTC.

These are security-fix releases. The highest severity issue fixed in
each of these two releases is Moderate:
11:46:16
@ghishadow:matrix.orgghishadow changed their profile picture.12:52:11
19 Oct 2023
@delroth:delroth.netdelrothApache 2.4.58: https://downloads.apache.org/httpd/CHANGES_2.4.58 (CVE-2023-45802, CVE-2023-43622, CVE-2023-31122)14:35:04
@delroth:delroth.netdelroth * Apache 2.4.58: https://downloads.apache.org/httpd/CHANGES_2.4.58 (CVE-2023-45802, CVE-2023-43622, CVE-2023-31122) https://github.com/NixOS/nixpkgs/pull/262075 14:35:44
20 Oct 2023
@lt1379:matrix.orgLunRecent zlib CVE, don't know if this needs patched quickly https://nvd.nist.gov/vuln/detail/CVE-2023-45853 https://github.com/madler/zlib/pull/84300:13:19

Show newer messages


Back to Room ListRoom Version: 6