!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

691 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
12 Dec 2024
@metanoic:matrix.org@metanoic:matrix.org left the room.19:06:45
15 Dec 2024
@maridonkers:matrix.org@maridonkers:matrix.org joined the room.08:24:36
16 Dec 2024
@ksonj:matrix.org@ksonj:matrix.org left the room.14:59:37
17 Dec 2024
@sigmasquadron:matrix.orgSigmaSquadron

Hi all. Today, the Xen Project has publicly released CVE-2024-53240 (Xen Security Advisory #465) and CVE-2024-53241 (Xen Security Advisory #466).

We are not affected by the latter: It's a Linux guest issue regarding ret speculations. The Xen patch is just documentation, not hypervisor code. The Linux patches for #466, to the best of my knowledge, are unnecessary, as our kernels are not built with CONFIG_RETHUNK enabled, which mitigates this vulnerability.

We are, however, affected by the former vulnerability (#455) — a hypervisor crash caused by a malicious Linux 6.1+ guest who is allowed to suspend and resume. The issue lies in Xen's Linux guest drivers, not with the hypervisor itself. It's a single patch to drivers/net/xen-netfront.c. Can we get this patched in our kernels? (I know nothing about nixpkgs' kernel infrastructure. Do I just add a patch here?)

12:26:40
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] to tlaurion aka Insurgo [UTC-4] - last crush before holidays!.19:19:38
18 Dec 2024
@hexa:lossy.networkhexahttps://github.com/FiloSottile/age/releases/tag/v1.2.115:35:48
@hexa:lossy.networkhexahttps://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c15:35:52
@adam:robins.wtfadamcstephenshttps://github.com/NixOS/nixpkgs/pull/36620716:07:28
@dmiskovic:matrix.org@dmiskovic:matrix.org joined the room.19:37:45
19 Dec 2024
@hexa:lossy.networkhexaRedacted or Malformed Event15:54:23
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2024/12/19/1 sssd illustris 15:56:07
@hexa:lossy.networkhexa

misskey

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:57:55
@hexa:lossy.networkhexa *

misskey needs update to 2024.11.0-alpha.3 (sigh)

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:58:27
@hexa:lossy.networkhexa *

misskey needs update to 2024.11.0

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:58:58
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/36658816:20:10
@os:matrix.flyingcircus.ioosnyx (he/him)Percona update, that fixes the CVEs of the corresponding oracle mysql: https://github.com/NixOS/nixpkgs/pull/36657918:10:02
20 Dec 2024
@niklaskorz:korz.devNiklas KorzMatomo 4 has reached EOL yesterday16:34:53
@hexa:lossy.networkhexa osnyx (he/him): ^ 16:35:25
@hexa:lossy.networkhexa * osnyx (he/him), ma27 ^ 16:35:46
@ma27:nicht-so.sexyma27I'm perfectly fine with marking it as insecure on stable, just don't have the time to review now.17:06:17
@leona:leona.isleonaI will have a look in a few mins17:42:30
@labataxe:matrix.orglabataxe joined the room.18:47:16
21 Dec 2024
@stablejoy:matrix.org@stablejoy:matrix.org left the room.05:08:23
@dmiskovic:matrix.org@dmiskovic:matrix.org left the room.05:13:45
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] - last crush before holidays! to tlaurion aka Insurgo [UTC-4] - Back 2025-01-06.21:20:18
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.21:37:43
22 Dec 2024
@allrealmsoflife:matrix.orgallrealmsoflife joined the room.15:55:06
@hexa:lossy.networkhexa https://vikunja.io/changelog/vikunja-v0.24.6-was-released leona 21:05:01
@leona:leona.isleona https://github.com/NixOS/nixpkgs/pull/367467 21:30:37
@hexa:lossy.networkhexa leona: as 0.23.0 is affected, can you make the package vulnerable on 24.05? 21:48:08

Show newer messages


Back to Room ListRoom Version: 6