!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

760 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
14 Jun 2026
@hexa:lossy.networkhexaperl maintainers have been requested23:45:14
15 Jun 2026
@stigo:matrix.orgstigoCritical is probably pushing it a bit, that CVSS score comes from CISA btw12:16:46
@tcllama:matrix.orgtcllama joined the room.18:39:14
17 Jun 2026
@k900:0upti.meK900 https://www.cve.org/CVERecord?id=CVE-2026-42530 nginx vuln just dropped 17:15:52
@hexa:lossy.networkhexah3 only17:17:25
@hexa:lossy.networkhexa1.30.x is not yet EOL17:18:28
@hexa:lossy.networkhexaso is it not vulnerable per https://my.f5.com/manage/s/article/K000161616?17:18:41
@hexa:lossy.networkhexa
Download
17:18:55
@r-burns:matrix.orgr-burns joined the room.19:14:06
@r-burns:matrix.orgr-burnsPR to address CVE-2026-12043 HIGH Heap double-free in AWS Common Runtime https://github.com/NixOS/nixpkgs/pull/531504 Messaging here because this is a dependency of Nix via its AWS support which is typically enabled by default. Not sure of the severity here, perhaps low because it's only a concern if fetching a path from a compromised S3 bucket? Or perhaps not a concern at all if Nix only calls out to aws-c-common at runtime, not the aws-c-http component (not sure). Just wanted to point it out here so someone more knowledgeable can triage appropriately.19:22:52
@numinit:matrix.orgMorgan (@numinit)

https://lore.kernel.org/util-linux/c2fo4x3lcppsj77k564i4qodmon3wagx47qf4mqwjwdtiplupg@jmaqrlzp273h/T/

On it in a couple hours, looks like libmount stuff

22:30:59
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)
In reply to @r-burns:matrix.org
PR to address CVE-2026-12043 HIGH Heap double-free in AWS Common Runtime https://github.com/NixOS/nixpkgs/pull/531504 Messaging here because this is a dependency of Nix via its AWS support which is typically enabled by default. Not sure of the severity here, perhaps low because it's only a concern if fetching a path from a compromised S3 bucket? Or perhaps not a concern at all if Nix only calls out to aws-c-common at runtime, not the aws-c-http component (not sure). Just wanted to point it out here so someone more knowledgeable can triage appropriately.
The http component usage should be quite limited? This presumably also affects the cpp sdk (used by older nix versions)? If not, the http client usage should be limited to doing auth and such – the actual download is done by libcurl
22:33:29
@r-burns:matrix.orgr-burnsIt looks like modern nix 2.34 still links against it, just via aws-crt-cpp instead of aws-sdk-cpp. But yes, it looks like the only usage of AWS libs in modern nix is now in libstore/aws-creds.cc, which only appears to be using aws-c-auth and aws-c-io functionality. So yeah Nix is probably unaffected then, thanks for clarifying :)22:59:47
18 Jun 2026
@stigo:matrix.orgstigoI'm looking at all outstanding perlPackages vuln patches today12:12:33
@r-burns:matrix.orgr-burns ^ maybe not fully accurate as aws-c-auth appears to call out to aws-c-http internally, but they're not interacted with directly by Nix, at least 13:39:22
19 May 2021
@grahamc:nixos.org@grahamc:nixos.org set the history visibility to "world_readable".22:57:54
@grahamc:nixos.org@grahamc:nixos.org changed the room name to "" from "".22:57:54
@andreas.schraegle:helsinki-systems.deajs124 joined the room.22:58:46
@andi:kack.itandi- joined the room.23:00:51
@hexa:lossy.networkhexa joined the room.23:01:24
@sushi_dude:matrix.orgSushi Dude joined the room.23:04:45
@0x4a6f:matrix.org[0x4A6F] joined the room.23:04:54
@sumner:sumnerevans.comsumner joined the room.23:11:04
@sugi:matrix.besaid.desugi joined the room.23:24:52
@foxboron:archlinux.orgFoxboron joined the room.23:32:00
@adisbladis:matrix.orgadisbladis joined the room.23:43:35
20 May 2021
@sandro:supersandro.deSandro joined the room.00:06:39
@schatztruhe:stratum0.orgnora joined the room.00:31:53
@mkos:matrix.orgMark joined the room.00:38:14
@andreas.schraegle:helsinki-systems.deajs124 changed their display name from Andreas Schrägle to ajs124.00:40:47

Show newer messages


Back to Room ListRoom Version: 6