NixOS Security Triage | 699 Members | |
| Coordination and triage of security issues in nixpkgs | 216 Servers |
| Sender | Message | Time |
|---|---|---|
| 30 Jun 2025 | ||
| * libxml2 (cc Jan Tojnar i guess...): https://github.com/NixOS/nixpkgs/pull/418280 https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.14.4 https://access.redhat.com/security/cve/CVE-2025-6021 (apparently our bump to tip-of-branch got lucky and includes the cve fix, oh well) | 09:16:24 | |
| https://www.openwall.com/lists/oss-security/2025/06/30/3 https://www.openwall.com/lists/oss-security/2025/06/30/2 | 16:32:22 | |
| 17:16:27 | ||
| 17:17:27 | ||
| https://github.com/NixOS/nixpkgs/pull/421314 | 19:31:01 | |
| python setuptools CVE 7.7 (only 25.05): https://github.com/NixOS/nixpkgs/pull/421343 | 21:18:40 | |
| * python setuptools CVE 7.7 (only 25.05): https://github.com/NixOS/nixpkgs/pull/421350 | 21:48:50 | |
| 1 Jul 2025 | ||
| 03:29:06 | ||
| Hey Security Team In case you haven't seen the recent post on discourse, the Marketing Team is preparing this year's community survey. I am reaching out to teams to see if there are any questions they would like to add to the survey to better serve the work you all do. More details in the post linked below. https://discourse.nixos.org/t/community-feedback-requested-2025-nix-community-survey-planning/66155 | 03:29:17 | |
| 05:10:22 | ||
| https://openssl-library.org/news/secadv/20250522.txt Markus Theil | 12:17:09 | |
| Thx for the hint. Will add a PR this evening. | 13:57:22 | |
| All mentioned CVEs are also fixed in the PR for 3.5.0 already merged to staging. Currently used version 3.4.x are not affected. | 13:58:26 | |
| XSA #470: https://github.com/NixOS/nixpkgs/pull/421514 | 14:19:12 | |
| * XSA #470: https://github.com/NixOS/nixpkgs/pull/421514 | 14:19:50 | |
| on it. does it need backporting? | 14:39:36 | |
| 14:55:33 | ||
| https://github.com/NixOS/nixpkgs/pull/421531 is still compiling on my side. Will ping here, when ready and some smoke tests are done. | 15:33:21 | |
In reply to @emilazy:matrix.orgyep, forgot the label, sorry. | 15:57:16 | |
| 20:54:51 | ||
| 2 Jul 2025 | ||
| OpenSSL is ready. Update for 25.05 in https://github.com/NixOS/nixpkgs/pull/421735 | 09:43:52 | |
| 4 Jul 2025 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572
| 07:53:03 | |
| * https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572
| 07:54:17 | |
| * https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572
| 07:55:50 | |
| there might well be more, seems some new people started actually fuzzing that lib. There is POCs and all, but assigned severity is all somewhat low. Still safe to say the next release is security-relevant | 07:57:13 | |
| * https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572
| 08:00:54 | |
| assimp: https://github.com/NixOS/nixpkgs/pull/422357 CVE-2025-2751: GHSA-345v-qrhv-w227 CVE-2025-2757: GHSA-4p6w-747g-444c CVE-2025-2750: GHSA-6x45-4j6r-r8x8 CVE-2025-3158: GHSA-6r79-vpvw-rfjj | 10:42:06 | |
Download image.png | 10:42:56 | |
| K900: oh yeah I ran into a fun thing | 11:06:15 | |
| er | 11:06:24 | |