!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

667 Members
Coordination and triage of security issues in nixpkgs212 Servers

Load older messages


SenderMessageTime
20 May 2025
@emilazy:matrix.orgemily(fixed aliases merge conflict 🙃)13:24:32
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/05/20/2 openvpn15:30:00
@hexa:lossy.networkhexa

All versions from v20 through v24 are affected. This has been resolved
in OpenVPN 3 Linux v24.1.

15:30:15
@hexa:lossy.networkhexa
nix-repl> :p openvpn3.version
24
15:30:30
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/40911916:37:41
21 May 2025
@zhaofeng:zhaofeng.liZhaofeng Lilibarchive: https://github.com/NixOS/nixpkgs/pull/409300 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 Security fixes mixed with new features, no CVEs assigned as far as I can tell06:46:07
@stigo:matrix.orgstigoI've pinged Red Hat about it, hopefully they will get CVEs fixed10:26:12
@stigo:matrix.orgstigo(MITRE takes ages to repond)10:28:23
@oddlama:matrix.orgoddlama changed their display name from Malte to oddlama.17:42:18
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/40944523:56:59
23 May 2025
@stigo:matrix.orgstigoRed Hat CNA-LR responded yesterday that they will process the issues11:04:13
@mtheil:scs.ems.hostMarkus Theilhttps://openssl-library.org/news/vulnerabilities/#CVE-2025-457513:18:08
@mtheil:scs.ems.hostMarkus TheilI commented the CVE in https://github.com/NixOS/nixpkgs/pull/397123.13:19:24
@alisonjenkins:matrix.orgAlison Jenkins changed their profile picture.16:05:41
25 May 2025
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/05/23/215:50:31
@hexa:lossy.networkhexa* https://www.openwall.com/lists/oss-security/2025/05/23/2 ghostscript15:50:49
26 May 2025
@ximnoise:infosec.exchangeximnoise left the room.02:57:15
@ximnoise:infosec.exchangeximnoise joined the room.02:57:30
27 May 2025
@deeok:matrix.orgmatrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms) joined the room.07:49:31
@irenes:matrix.org@irenes:matrix.org left the room.09:00:51
@mdaniels5757:matrix.orgmdaniels5757 joined the room.23:45:31
28 May 2025
@numinit:matrix.orgMorgan (@numinit)

https://www.openwall.com/lists/oss-security/2025/05/28/4

https://curl.se/docs/CVE-2025-4947.html

curl (only wolfssl as a backend though)

05:53:27
@vcunat:matrix.orgvcunatThat seems to be only opt-in in nixpkgs. So a patch can be applied conditionally without any rebuild (and users of it will probably be rare here).06:03:22
@vcunat:matrix.orgvcunatMerged, but honestly I don't know what to do about stable nixpkgs.09:57:17
@emilazy:matrix.orgemilyseems backportable? is there anything breaking I'm missing?11:10:30
@zhaofeng:zhaofeng.liZhaofeng Li

Is the concern about the new features?

(not sure if replying in a thread will cause notifications - if so, let's move to #security-discuss:nixos.org )

15:42:37
29 May 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://github.com/NixOS/nixpkgs/issues/411881 so uh - do we pick commits into our jq? one of the two doesn't even have a fix commit, and i'd be surprised if the fix for the other actually applies properly...09:26:03
@k900:0upti.meK900What the lol09:26:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)jq had no release since 2023, but now the second 7.5+ cve09:27:21
@k900:0upti.meK900Has anyone rewritten it in rust yet09:27:37

Show newer messages


Back to Room ListRoom Version: 6