!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

641 Members
Coordination and triage of security issues in nixpkgs205 Servers

Load older messages


SenderMessageTime
11 Dec 2024
@hexa:lossy.networkhexahttps://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/16:00:02
@hexa:lossy.networkhexa xanderio, leona ^ 16:01:05
@hexa:lossy.networkhexaRedacted or Malformed Event16:01:47
@hexa:lossy.networkhexaI'm too slow 🙂 16:01:49
@leona:leona.isleona
In reply to @hexa:lossy.network
https://about.gitlab.com/releases/2024/12/11/patch-release-gitlab-17-6-2-released/
there are already two open PRs for that: https://github.com/NixOS/nixpkgs/pull/364213 https://github.com/NixOS/nixpkgs/pull/364219 (24.05 as 'hotter' fix)
16:01:52
@stick:matrix.orgprusnak left the room.18:36:40
@fernsehmuell:matrix.orgfernsehmuell (he/his) changed their display name from fernsehmuell to fernsehmuell (he/his) DECT: 3376 (fern).18:57:11
12 Dec 2024
@niklaskorz:korz.devNiklas Korz

unless someone's already on it, I'd create two (or three) PRs today:

  • unstable: move matomo to 5.1.2 and alias matomo_5 to matomo (+ release notes)
  • 24.11: add knownVulnerabilities to matomo about EOL and recommend an upgrade to matomo_5 (+ release notes)
  • same for 24.05 or should it be skipped because it's EOL in three weeks?
08:30:47
@tgerbet:matrix.orgtgerbetIdeally same for 24.0508:33:49
@sandro:supersandro.deSandroIf we only would build packages with knowVulnerabilities then we wouldn't need to weigh usability and security against each other 09:50:42
@niklaskorz:korz.devNiklas Korz as someone relying on a handful of libolm based services and applications, I tend to agree 10:05:17
@flanitz:matrix.flyingcircus.ioFrank LanitzAll software is full of unfixed, known issues ;)10:09:19
@phileas:asra.grsyd installs gentoo (they/them)Reminder there is also #security-discuss:nixos.org (though I can't join the channel for some reason)10:15:55
@ahurac:chat.ahur.acAhurac left the room.10:16:08
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.14:33:59
@niklaskorz:korz.devNiklas Korz
  • unstable: https://github.com/NixOS/nixpkgs/pull/364627
  • 24.11: https://github.com/NixOS/nixpkgs/pull/364633
  • 24.05: https://github.com/NixOS/nixpkgs/pull/364642
16:17:22
@metanoic:matrix.org@metanoic:matrix.org left the room.19:06:45
15 Dec 2024
@maridonkers:matrix.orgThe Photonsphere joined the room.08:24:36
16 Dec 2024
@ksonj:matrix.org@ksonj:matrix.org left the room.14:59:37
17 Dec 2024
@sigmasquadron:matrix.orgSigmaSquadron

Hi all. Today, the Xen Project has publicly released CVE-2024-53240 (Xen Security Advisory #465) and CVE-2024-53241 (Xen Security Advisory #466).

We are not affected by the latter: It's a Linux guest issue regarding ret speculations. The Xen patch is just documentation, not hypervisor code. The Linux patches for #466, to the best of my knowledge, are unnecessary, as our kernels are not built with CONFIG_RETHUNK enabled, which mitigates this vulnerability.

We are, however, affected by the former vulnerability (#455) — a hypervisor crash caused by a malicious Linux 6.1+ guest who is allowed to suspend and resume. The issue lies in Xen's Linux guest drivers, not with the hypervisor itself. It's a single patch to drivers/net/xen-netfront.c. Can we get this patched in our kernels? (I know nothing about nixpkgs' kernel infrastructure. Do I just add a patch here?)

12:26:40
@insurgo:matrix.orgtlaurion aka Insurgo [UTC-4] changed their display name from tlaurion aka Insurgo [UTC-4] to tlaurion aka Insurgo [UTC-4] - last crush before holidays!.19:19:38
18 Dec 2024
@hexa:lossy.networkhexahttps://github.com/FiloSottile/age/releases/tag/v1.2.115:35:48
@hexa:lossy.networkhexahttps://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c15:35:52
@adam:robins.wtfadamcstephenshttps://github.com/NixOS/nixpkgs/pull/36620716:07:28
@dmiskovic:matrix.org@dmiskovic:matrix.org joined the room.19:37:45
19 Dec 2024
@hexa:lossy.networkhexaRedacted or Malformed Event15:54:23
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2024/12/19/1 sssd illustris 15:56:07
@hexa:lossy.networkhexa

misskey

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:57:55
@hexa:lossy.networkhexa *

misskey needs update to 2024.11.0-alpha.3 (sigh)

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:58:27
@hexa:lossy.networkhexa *

misskey needs update to 2024.11.0

  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-m2gq-69fp-6hv4
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-7vgr-p3vc-p4h2
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5h8r-gq97-xv69
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-gq5q-c77c-v236
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-5q3h-wpfw-hjjw
  • https://github.com/misskey-dev/misskey/security/advisories/GHSA-675w-hf2m-qwmj
15:58:58

Show newer messages


Back to Room ListRoom Version: 6