!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

657 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22204 Servers

Load older messages


SenderMessageTime
15 Nov 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)thanks for the heads up though!19:01:02
@leona:leona.isleonaWhen we scrap the cycle we need to move the release almost certainly. I really really want this cycle to be finished as early as possible, otherwise this will break our neck.19:12:21
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)then i vote to wait with this until the next cycle and backport to get it into 25.1119:31:01
@hexa:lossy.networkhexathe issue with that is that we'll have three staging branches at that point 😄 19:53:10
@hexa:lossy.networkhexathere is no good choice fwiw19:53:22
@hexa:lossy.networkhexa* there is no great choice fwiw19:53:37
@vcunat:matrix.orgvcunatI'd leave it for the next cycle.23:04:11
17 Nov 2025
@karlericsson:matrix.orgkarlericsson joined the room.13:14:05
18 Nov 2025
@grimmauld:m.grimmauld.degrimmauld (any/all) joined the room.08:16:51
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) i have a fix in the attachment, but can't open a PR. It just cleanly applies, both on 2.15.1 and 2.13. Can't open a PR rn because github is down, will do that once its back 20:57:13
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Download 0001-libxml2-fetch-patch-fixing-CVE-2025-12863-in-xmlSetT.patch20:57:13
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)* i have a fix in the attachment, but can't open a PR. Upstream patch just cleanly applies, both on 2.15.1 and 2.13. Can't open a PR rn because github is down, will do that once its back21:12:57
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/20021:49:05
@hexa:lossy.networkhexaalready fixed on master21:49:23
@hexa:lossy.networkhexabut the version on 25.05 is being put into question21:50:14
@hexa:lossy.networkhexa* but the version (3.48.0) on 25.05 is being put into question21:50:23
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) https://github.com/NixOS/nixpkgs/pull/463018 22:23:38
19 Nov 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) https://gitlab.gnome.org/GNOME/libxml2/-/issues/1012#note_2608283
So the supposed libxml2 vulnerability is now contested by the main developer, saying it isn't even a vulnerability and instead is documented behavior. We might not actually have to do anything.
13:44:14
@pyrox:pyrox.devdish [Fox/It/She]still terrible api design though >.>16:13:05
@tgerbet:matrix.orgtgerbet

https://www.openwall.com/lists/oss-security/2025/11/18/1

I will deal with it and continue to expand the never ending list of patches of grub2 🫠

19:58:53
20 Nov 2025
@fernsehmuell:matrix.orgfernsehmuell (☎️ 3376 he/him) changed their display name from fernsehmuell (he/his) to fernsehmuell (☎️ 3376 he/him).00:19:06
@user12592851:matrix.orgJohn joined the room.05:11:05
@cve:entropia.decve joined the room.13:42:24
@cve:entropia.decve

Would someone mind having a look at 462970 and 463034?

Both pull requests are open for close to two days by now and they fix a medium-severity security vulnerability in Tor, potentially leading to a remote crash.

Besides, relays on the old version are also no longer advertised in the current Tor consensus, meaning they now display a scary red warning too.

13:53:22
@cve:entropia.decve *

Would someone mind having a look at 462970 and 463034?

Both pull requests fix a medium-severity security vulnerability in Tor, potentially leading to a remote crash.

Besides, relays on the old version are also no longer advertised in the current Tor consensus, meaning they now display a scary red warning too.

13:53:38
@yzhyhalo:matrix.orgYevhen Zhyhalo joined the room.16:09:00
@hexa:lossy.networkhexa https://www.gnutls.org/security-new.html#GNUTLS-SA-2025-11-18 gnutls vcunat 19:21:32
@hexa:lossy.networkhexa3.8.11 basically19:21:44
@vcunat:matrix.orgvcunathttps://github.com/NixOS/nixpkgs/pull/46347019:21:55
21 Nov 2025
@amadaluzia:unredacted.orgamadaluzia (🇹🇷 til 25th) changed their display name from amadaluzia to amadaluzia (in 🇹🇷 til 25).14:44:25

Show newer messages


Back to Room ListRoom Version: 6