!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

661 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
10 Oct 2025
@niklaskorz:matrix.orgniklaskorzhttps://github.com/NixOS/nixpkgs/pull/45072916:48:13
11 Oct 2025
@midischwarz12:libg.somidischwarz12 joined the room.21:01:41
12 Oct 2025
@midischwarz12:libg.somidischwarz12 removed their profile picture.02:45:02
@midischwarz12:libg.somidischwarz12 set a profile picture.02:45:11
@anton:gersthof.comAnton (he/him) changed their display name from Anton to Anton (he/him).13:18:01
13 Oct 2025
@niklaskorz:matrix.orgniklaskorznvidia 535 update with beforementioned CVE fixes: https://github.com/NixOS/nixpkgs/pull/45161809:43:33
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/2621:54:56
@hexa:lossy.networkhexa* https://seclists.org/oss-sec/2025/q4/26 boringssl21:55:02
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2025/q4/27 poppler21:55:17
@hexa:lossy.networkhexarequires poppler-25.10.022:27:01
@hexa:lossy.networkhexa * requires poppler-25.10.0 (Jan Tojnar) 22:27:09
@hexa:lossy.networkhexahttps://gitlab.freedesktop.org/poppler/poppler/-/commit/4ce27cc826bf90cc8dbbd8a8c87bd913cccd7ec022:27:29
@hexa:lossy.networkhexahttps://webkitgtk.org/security/WSA-2025-0007.html webkitgtk23:11:01
14 Oct 2025
@vcunat:matrix.orgvcunatThe boringssl thread doesn't seem very convincing, i.e. no claim is made that the leak goes beyond key length and similar "uninteresting" parameters.08:56:06
@vcunat:matrix.orgvcunatAll crypto libs will take longer time when using longer keys, I believe. (up to some exceptions maybe when the difference in length is small)08:57:39

Show newer messages


Back to Room ListRoom Version: 6