!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

661 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
4 Jul 2025
@emilazy:matrix.orgemilyer11:06:24
@emilazy:matrix.orgemilywrong room sorry11:06:26
6 Jul 2025
@jammie:matrix.org@jammie:matrix.org left the room.02:28:02
@cathal_mullan:matrix.orgCathal changed their display name from CJ to Cathal.17:17:33
7 Jul 2025
@leona:leona.isleonahttps://github.com/NixOS/nixpkgs/pull/421805 keycloak security update06:51:59
@saiko:knifepoint.net@saiko:knifepoint.net changed their display name from Katalin ⚧︎ to Katalin 🔪.23:27:41
9 Jul 2025
@jonhermansen:matrix.orgjonhermansen joined the room.01:01:41
@phileas:asra.grsyd installs gentoo (they/them)https://dgl.cx/2025/07/git-clone-submodule-cve-2025-48384 git clone --recursive RCE CVE-2025-4838411:10:20
@k900:0upti.meK900 Known, we're deciding how to best handle it 11:21:38
10 Jul 2025
@vcunat:matrix.orgvcunat

I just noticed our intel-media-sdk; upstream says

This project will no longer be maintained by Intel.
This project has been identified as having known security escapes.

We use it in particular in ffmpeg-full. No idea how big a risk it is in there.

08:32:52
@hexa:lossy.networkhexahttps://security-tracker.debian.org/tracker/source-package/intel-mediasdk12:14:24
@hexa:lossy.networkhexaremoved from debian in 2024-1012:15:01
@hexa:lossy.networkhexaother distros, e.g. fedora, are still shipping it12:15:10
@hexa:lossy.networkhexa -> #security-discuss:nixos.org 12:16:15
@vcunat:matrix.orgvcunat

gnutls had a security release yesterday:
https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html

Maybe I could have a look within several hours.

12:17:14
@vcunat:matrix.orgvcunat25.05 will probably need to pick the CVE patches. For staging: https://github.com/NixOS/nixpkgs/pull/42409516:38:33
@fr0de_0xa:matrix.orgFred Lahde joined the room.18:48:25

Show newer messages


Back to Room ListRoom Version: 6