!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

691 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
29 Oct 2024
@scrumplex:duckhub.ioScrumplex * I can submit a PR but I don't think I'll be able to test them beyond building them Edit: PR: https://github.com/NixOS/nixpkgs/pull/35219121:16:01
30 Oct 2024
@stigo:matrix.orgstigoThis seems to have been merged into staging, any ETA on when this fix will arrive in the unstable channels?11:22:08
@lt1379:matrix.orgLunhttps://github.com/NixOS/nixpkgs/issues/35244519:24:20
@vcunat:matrix.orgvcunatLike... a month, I'd guess.19:25:32
@emilazy:matrix.orgemily uh, we're doing one more staging before release though right? 19:26:10
@emilazy:matrix.orgemilythere's some pretty important fixes in there19:26:14
@emilazy:matrix.orgemilyand the schedule calls for it19:26:22
@emilazy:matrix.orgemily I thought we would go straight into staging-next-24.05 in a couple days when we merge, and then do one last 24.11-pre. 19:26:55
@grossmap:in.tum.de@grossmap:in.tum.de joined the room.19:59:46
@joerg:thalheim.ioMic92https://github.com/NixOS/nixpkgs/pull/352455 https://github.com/NixOS/nixpkgs/pull/35245620:36:43
@joerg:thalheim.ioMic92nix: fix macOS sandbox escape via builtin builders20:36:55
@emilazy:matrix.orgemilyRedacted or Malformed Event20:44:35
@emilazy:matrix.orgemilywill handle this one20:48:58
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2024/10/30/4 qbittorrent23:55:19
31 Oct 2024
@scrumplex:duckhub.ioScrumplexhttps://github.com/NixOS/nixpkgs/pull/352499 for master00:11:01
@scrumplex:duckhub.ioScrumplex24.05 is on 4.x. Just blindly applying the relevant patches doesn't work Relevant patch: https://github.com/qbittorrent/qBittorrent/commit/2a4425380292baedc3be1d1e57506e45172da6fc Part of the same PR but not strictly needed to fix vulnerability: https://github.com/qbittorrent/qBittorrent/commit/2a4077414f44f370d4bb66c3fd91ec755d4ce04d00:17:48
@emilazy:matrix.orgemily the advisory is somewhat (subtextually) withering about their security practices. I think knownVulnerabilities for 24.05 is okay, and it's not clear to me if the other issues they disclosed have been fixed. 00:18:32
@emilazy:matrix.orgemily * the advisory is somewhat (subtextually) withering about their security practices. I think knownVulnerabilities for 24.05 is okay, and it's not clear to me if the other issues they disclosed have been fixed. (edit: actually, I guess they implied they're at least unexploitable due to TLS validation now) 00:19:12
@scrumplex:duckhub.ioScrumplexI'll propose this: https://github.com/NixOS/nixpkgs/pull/352501 Maybe we can safely update 24.05 to qBittorrent 5.0.1, as I couldn't see any breaking changes, but maybe other people can handle that ^^00:21:57
@scrumplex:duckhub.ioScrumplex

Buffer overflow in libmpg123:

https://www.openwall.com/lists/oss-security/2024/10/30/2

00:37:32
@scrumplex:duckhub.ioScrumplex *

Buffer overflow in libmpg123:

https://www.openwall.com/lists/oss-security/2024/10/30/2

CVE-2024-10573

00:37:59
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2024/10/31/1 webkitgtk 2.46.3 Jan Tojnar 01:04:50
@vcunat:matrix.orgvcunat
In reply to @scrumplex:duckhub.io

Buffer overflow in libmpg123:

https://www.openwall.com/lists/oss-security/2024/10/30/2

CVE-2024-10573

https://github.com/NixOS/nixpkgs/pull/351584
06:39:26
@jtojnar:matrix.orgJan Tojnarsorry, not sure if I will be able to get to it this week09:27:35
1 Nov 2024
@tomodachi94:matrix.orgTomodachi94 (they/them) joined the room.19:18:47
2 Nov 2024
@matrix:03j.de@matrix:03j.de joined the room.00:16:13
4 Nov 2024
@aleksana:mozilla.orgaleksana 🏳️‍⚧️ (force me to bed after 18:00 UTC)Someone reported on hacker news that yt-dlp 2024.10.22 (which we are also using) has malicious behavior: https://news.ycombinator.com/item?id=4204060012:03:10
@aleksana:mozilla.orgaleksana 🏳️‍⚧️ (force me to bed after 18:00 UTC)No conclusion has been drawn yet12:04:27
@sandro:supersandro.deSandrowe are not using the prebuilt binaries in the first place and the actual content is also being disputed 15:52:07
@martijn:plebian.nlmartijn joined the room.18:41:25

Show newer messages


Back to Room ListRoom Version: 6