!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

639 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22200 Servers

Load older messages


SenderMessageTime
11 Jul 2025
@felix.schroeter:scs.ems.hostFelix Schröter joined the room.16:58:53
12 Jul 2025
@hexa:lossy.networkhexahttps://github.com/NixOS/nix/security/advisories/GHSA-qc7j-jgf3-qmhg12:15:00
@emilazy:matrix.orgemily handling nixVersions.git 13:22:35
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/42459313:33:13
@emilazy:matrix.orgemilytesting build on Darwin, if someone could get Linux that would be cool13:33:24
@xokdvium:matrix.orgSergei Zimmerman (xokdvium) joined the room.14:08:27
@xokdvium:matrix.orgSergei Zimmerman (xokdvium) Backport bot having issues on emily's PR. Manual backport I've opened at the same time https://github.com/NixOS/nixpkgs/pull/424592.
Will merge when darwin build finishes.
14:10:48
14 Jul 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) *

https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572
https://nvd.nist.gov/vuln/detail/CVE-2025-6816 | https://github.com/HDFGroup/hdf5/issues/5571
https://nvd.nist.gov/vuln/detail/CVE-2025-6750 | https://github.com/HDFGroup/hdf5/issues/5549
https://nvd.nist.gov/vuln/detail/CVE-2025-6516 | https://github.com/HDFGroup/hdf5/issues/5581
https://nvd.nist.gov/vuln/detail/CVE-2025-6270 | https://github.com/HDFGroup/hdf5/issues/5580
https://nvd.nist.gov/vuln/detail/CVE-2025-6269 | https://github.com/HDFGroup/hdf5/issues/5579
https://nvd.nist.gov/vuln/detail/CVE-2025-7069 | https://github.com/HDFGroup/hdf5/issues/5550
https://nvd.nist.gov/vuln/detail/CVE-2025-7068 | https://github.com/HDFGroup/hdf5/issues/5578
https://nvd.nist.gov/vuln/detail/CVE-2025-7067 | https://github.com/HDFGroup/hdf5/issues/5577

hdf5 doesn't have a new release, and none of these CVEs have patches yet either. I'll be watching the issues, i have my own projects that depend on hdf5 (bachelors thesis) but figured i might as well post these here too. Fix will likely only come out in September.

07:07:15

There are no newer messages yet.


Back to Room ListRoom Version: 6