!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

690 Members
Coordination and triage of security issues in nixpkgs215 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
20 Aug 2024
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its) changed their display name from sophie to ⛧-440729 [sophie] (it/its).20:59:39
22 Aug 2024
@jaredbaur:matrix.orgJared Baur set a profile picture.02:07:15
@jassu:kumma.juttu.asiaJassukoPreviously semi-concerning FFmpeg CVEs seem to now have POC RCE published. Probably worth bumping the versions to the safe side rather soon. https://securityonline.info/cve-2024-7272-critical-heap-overflow-vulnerability-discovered-in-ffmpeg-poc-published/ CVE-2024-7272: Critical Heap Overflow Vulnerability Discovered in FFmpeg, PoC Published13:08:28
@hexa:lossy.networkhexa emily maybe? 13:09:29
@emilazy:matrix.orgemilyI think we have all the versions up to date13:36:10
@emilazy:matrix.orgemilyat least in staging 🫠13:36:14
@emilazy:matrix.orgemilyI'll check…13:36:24
@emilazy:matrix.orgemilyurgh this blogspam, where's the actual upstream announcement13:37:10
@emilazy:matrix.orgemilyokay so FFmpeg 4 is actually known vulnerable now??13:37:30
@jassu:kumma.juttu.asiaJassukoSorry, didn't find proper announcement, just the new releases on the release page: https://ffmpeg.org/download.html#releases13:38:59
@emilazy:matrix.orgemilyok, so https://github.com/NixOS/nixpkgs/pull/333021 is waiting for staging13:41:20
@emilazy:matrix.orgemilywe're on the latest 4 but the CVE says "A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5"13:41:31
@emilazy:matrix.orgemilyso there's no patch for 4?13:41:49
@emilazy:matrix.orgemily let's see if we can backport the commit. anyway, taking this to #security-discuss:nixos.org I guess 13:42:09
@niko:puppygock.gaynyanbinary 🏳️‍⚧️ left the room.17:19:37
@tgerbet:matrix.orgtgerbet networkException: https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html 20:53:38
@hexa:lossy.networkhexa networkException, emily 20:55:46
@hexa:lossy.networkhexabah, too slow20:56:00
@hexa:lossy.networkhexaexcuse me20:56:07

Show newer messages


Back to Room ListRoom Version: 6