!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

704 Members
Coordination and triage of security issues in nixpkgs217 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
24 Jan 2025
@grimmauld:grimmauld.deGrimmauld (moving to @grimmauld:grapevine.grimmauld.de) * update: Not really fixable; SDL2_ttf exists and fixes these vulnerabilities, the newest SDL1-based SDL_ttf is vulnerable. So even if we update from the current version (2.0.11, released in 2013) to the newest (2.0.18, released in 2022) this wouldn't actually fix the vuln. So i suppose the correct way is to update the dependents instead? 11:43:08
@emilazy:matrix.orgemilywe should really drop sdl111:51:58
@emilazy:matrix.orgemilyjust mark it known vulnerable for now11:52:44
@grimmauld:grimmauld.deGrimmauld (moving to @grimmauld:grapevine.grimmauld.de)This has the sideeffect of breaking all appimage-based packages. Now i do hate appimage, but we shouldn't break them. https://github.com/NixOS/nixpkgs/blame/defe5870670e9fe4d0a8a04e0e58ec60c7745bb1/pkgs/build-support/appimage/default.nix#L183C7-L183C14 lists it as included in the appimage environment, but that is 6 years old and the linked exclude list does not list anything related to sdl anymore. Do i just drop SDL1 ttf from appimage FHS?11:55:20
@grimmauld:grimmauld.deGrimmauld (moving to @grimmauld:grapevine.grimmauld.de)* This has the sideeffect of breaking all appimage-based packages. Now i do hate appimage, but we shouldn't break them. https://github.com/NixOS/nixpkgs/blame/defe5870670e9fe4d0a8a04e0e58ec60c7745bb1/pkgs/build-support/appimage/default.nix#L183C7-L183C14 lists it as included in the appimage environment, but that is 6 years old and the linked exclude list does not list anything related to sdl anymore. Do i just drop SDL1 things from appimage FHS?11:55:56
@emilazy:matrix.orgemilyIMO just drop SDL1 from there in general, highly doubt anything we package as an appimage needs it. (continue in the security discussions room?)11:56:42
@tgerbet:matrix.orgtgerbetDebian tracker lists the commit introducing the issue https://security-tracker.debian.org/tracker/CVE-2022-27470 Might want to check if it really impacts SDL1, I'm on mobile it is annoying to do (But yeah dropping old stuff like that is needed)12:04:33

Show newer messages


Back to Room ListRoom Version: 6