!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

718 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22221 Servers

Load older messages


SenderMessageTime
22 Jun 2026
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/issues/53292013:53:53
@hexa:lossy.networkhexa cc Sandro 🐧 13:54:14
@9lore:tchncs.de9lorefun13:56:06
@sandro:supersandro.deSandro 🐧I cannot remember why I ended up maintaining that package 😅15:42:36
@sandro:supersandro.deSandro 🐧Why are all the issues memory problems?! https://github.com/libssh2/libssh2/issues?q=sort%3Aupdated-desc+is%3Aissue+state%3Aopen+15:46:43
@sandro:supersandro.deSandro 🐧I asked upstream for a new release https://github.com/libssh2/libssh2/issues/211815:47:58
@bart:bartoostveen.nlBart

Few major CVEs on ffmpeg 5, 6 and 8:

CVE-2025-22921, CVE-2026-8461, CVE-2026-30997, CVE-2026-40962

https://github.com/NixOS/nixpkgs/pull/534374
https://github.com/NixOS/nixpkgs/pull/534379
https://github.com/NixOS/nixpkgs/pull/534378

(and ffmepg 4.4.8 while we're at it: https://github.com/NixOS/nixpkgs/pull/534377)

21:22:17
@bart:bartoostveen.nlBart I'm busy building, but it takes a long time :( 21:22:38
@bart:bartoostveen.nlBart *

Few major CVEs on ffmpeg 5, 6 and 8:

CVE-2025-22921, CVE-2026-8461, CVE-2026-30997, CVE-2026-40962

https://github.com/NixOS/nixpkgs/pull/534374 (staging)
https://github.com/NixOS/nixpkgs/pull/534379
https://github.com/NixOS/nixpkgs/pull/534378

(and ffmepg 4.4.8 while we're at it: https://github.com/NixOS/nixpkgs/pull/534377)

21:22:43
@bart:bartoostveen.nlBart *

Few major CVEs on ffmpeg 6, 7 and 8:

CVE-2025-22921, CVE-2026-8461, CVE-2026-30997, CVE-2026-40962

https://github.com/NixOS/nixpkgs/pull/534374 (staging)
https://github.com/NixOS/nixpkgs/pull/534379
https://github.com/NixOS/nixpkgs/pull/534378

(and ffmepg 4.4.8 while we're at it: https://github.com/NixOS/nixpkgs/pull/534377)

21:39:36
@bart:bartoostveen.nlBart *

Few major CVEs on ffmpeg 6, 7 and 8:

CVE-2025-22921, CVE-2026-8461, CVE-2026-30997, CVE-2026-40962

https://github.com/NixOS/nixpkgs/pull/534374 (staging)
https://github.com/NixOS/nixpkgs/pull/534379
https://github.com/NixOS/nixpkgs/pull/534378

(and ffmpeg 4.4.8 while we're at it: https://github.com/NixOS/nixpkgs/pull/534377)

21:39:48

There are no newer messages yet.


Back to Room ListRoom Version: 6