!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

675 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22210 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
20 May 2025
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/409063 https://github.com/NixOS/nixpkgs/pull/40906413:12:40
@emilazy:matrix.orgemily"Patches to fix CVE-2017-12921 and CVE-2017-12925 and possibly CVE-2017-12920." always a good time when the changelog isn't even sure they fixed the CVE13:13:06
@hexa:lossy.networkhexathis is imagemagick, you can always assume a vulnerability lingering13:16:33
@emilazy:matrix.orgemily(fixed aliases merge conflict 🙃)13:24:32
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2025/05/20/2 openvpn15:30:00
@hexa:lossy.networkhexa

All versions from v20 through v24 are affected. This has been resolved
in OpenVPN 3 Linux v24.1.

15:30:15
@hexa:lossy.networkhexa
nix-repl> :p openvpn3.version
24
15:30:30
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/40911916:37:41
21 May 2025
@zhaofeng:zhaofeng.liZhaofeng Lilibarchive: https://github.com/NixOS/nixpkgs/pull/409300 https://github.com/libarchive/libarchive/releases/tag/v3.8.0 Security fixes mixed with new features, no CVEs assigned as far as I can tell06:46:07
@stigo:matrix.orgstigoI've pinged Red Hat about it, hopefully they will get CVEs fixed10:26:12
@stigo:matrix.orgstigo(MITRE takes ages to repond)10:28:23
@oddlama:matrix.orgoddlama changed their display name from Malte to oddlama.17:42:18

Show newer messages


Back to Room ListRoom Version: 6