!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

681 Members
Coordination and triage of security issues in nixpkgs214 Servers

Load older messages


SenderMessageTime
18 Nov 2025
@grimmauld:m.grimmauld.degrimmauld (any/all) joined the room.08:16:51
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) i have a fix in the attachment, but can't open a PR. It just cleanly applies, both on 2.15.1 and 2.13. Can't open a PR rn because github is down, will do that once its back 20:57:13
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Download 0001-libxml2-fetch-patch-fixing-CVE-2025-12863-in-xmlSetT.patch20:57:13
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)* i have a fix in the attachment, but can't open a PR. Upstream patch just cleanly applies, both on 2.15.1 and 2.13. Can't open a PR rn because github is down, will do that once its back21:12:57
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/20021:49:05
@hexa:lossy.networkhexaalready fixed on master21:49:23
@hexa:lossy.networkhexabut the version on 25.05 is being put into question21:50:14
@hexa:lossy.networkhexa* but the version (3.48.0) on 25.05 is being put into question21:50:23
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) https://github.com/NixOS/nixpkgs/pull/463018 22:23:38
19 Nov 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) https://gitlab.gnome.org/GNOME/libxml2/-/issues/1012#note_2608283
So the supposed libxml2 vulnerability is now contested by the main developer, saying it isn't even a vulnerability and instead is documented behavior. We might not actually have to do anything.
13:44:14
@pyrox:pyrox.devdish [Fox/It/She]still terrible api design though >.>16:13:05
@tgerbet:matrix.orgtgerbet

https://www.openwall.com/lists/oss-security/2025/11/18/1

I will deal with it and continue to expand the never ending list of patches of grub2 🫠

19:58:53
20 Nov 2025
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) changed their display name from fernsehmuell (he/his) to fernsehmuell (☎️ 3376 he/him).00:19:06
@user12592851:matrix.orgJohn joined the room.05:11:05
@cve:entropia.decve joined the room.13:42:24
@cve:entropia.decve

Would someone mind having a look at 462970 and 463034?

Both pull requests are open for close to two days by now and they fix a medium-severity security vulnerability in Tor, potentially leading to a remote crash.

Besides, relays on the old version are also no longer advertised in the current Tor consensus, meaning they now display a scary red warning too.

13:53:22
@cve:entropia.decve *

Would someone mind having a look at 462970 and 463034?

Both pull requests fix a medium-severity security vulnerability in Tor, potentially leading to a remote crash.

Besides, relays on the old version are also no longer advertised in the current Tor consensus, meaning they now display a scary red warning too.

13:53:38
@yzhyhalo:matrix.orgYevhen Zhyhalo joined the room.16:09:00
@hexa:lossy.networkhexa https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-11-18 gnutls vcunat 19:21:32
@hexa:lossy.networkhexa3.8.11 basically19:21:44
@vcunat:matrix.orgvcunathttps://github.com/NixOS/nixpkgs/pull/46347019:21:55
21 Nov 2025
@amadaluzia:unredacted.orgamadaluzia changed their display name from amadaluzia to amadaluzia (in 🇹🇷 til 25).14:44:25
@amadaluzia:unredacted.orgamadaluzia changed their display name from amadaluzia (in 🇹🇷 til 25) to amadaluzia (🇹🇷 til 25th).14:45:11
22 Nov 2025
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/204 libpng13:31:44
@hexa:lossy.networkhexahttp://github.com/nixos/nixpkgs/pull/46398713:32:11
23 Nov 2025
@easel:matrix.org@easel:matrix.org left the room.01:50:39
24 Nov 2025
@amadaluzia:unredacted.orgamadaluzia changed their display name from amadaluzia (🇹🇷 til 25th) to amadaluzia.12:57:50
25 Nov 2025
@steeringwheelrules:tchncs.de@steeringwheelrules:tchncs.de left the room.18:12:22
26 Nov 2025
@mdaniels5757:matrix.orgmdaniels5757These PRs with security updates to packages (or their dependencies) have been approved by their respective maintainers, but still need to be merged. https://github.com/NixOS/nixpkgs/pull/463918 https://github.com/NixOS/nixpkgs/pull/464033 https://github.com/NixOS/nixpkgs/pull/46445102:38:48
@pyrox:pyrox.devdish [Fox/It/She]
In reply to @mdaniels5757:matrix.org
These PRs with security updates to packages (or their dependencies) have been approved by their respective maintainers, but still need to be merged. https://github.com/NixOS/nixpkgs/pull/463918 https://github.com/NixOS/nixpkgs/pull/464033 https://github.com/NixOS/nixpkgs/pull/464451
queued all, thank you
02:52:06

Show newer messages


Back to Room ListRoom Version: 6