!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

760 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
5 Jun 2026
@stigo:matrix.orgstigo https://github.com/NixOS/nixpkgs/pull/528021 <- perl issues 10:46:52
@zimbatm:numtide.comJonas Chevalier left the room.11:40:58
6 Jun 2026
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q2/822 freetype01:20:35
@whispers:catgirl.cloudwhispers [& it/fae]^ attempt at https://github.com/NixOS/nixpkgs/pull/52865203:54:33
@jkarlson:kapsi.fiEmil ThorsøeCan you elaborate on RCE, I see local privilege escalation?04:24:23
@k900:0upti.meK900 I can't read 07:35:06
7 Jun 2026
@arcayr:mischief.expertarcayri think the apache team figure cve-2026-49975 isn't worth a proper release, so my pr with the debian patches for it is probably going to be it for a while02:31:14
@arcayr:mischief.expertarcayrare we okay to fetchpatch2 from debian directly or would it be preferred to host the patches02:31:25
@arcayr:mischief.expertarcayri originally hosted them but figured it looks a bit more reliable and legitimate if they're actually from debian, idk02:31:57
@arcayr:mischief.expertarcayr * 02:32:06
@arcayr:mischief.expertarcayr * 02:32:13
@hexa:lossy.networkhexafetchpatch is fine02:37:47
@vcunat:matrix.orgvcunatFrom Debian you probably fetchurl, as they have it as a *file* in git.05:56:37
9 Jun 2026
@hexa:lossy.networkhexa Markus Theil are you doing the openssl updates? and 4.0? 12:05:38
10 Jun 2026
@arcayr:mischief.expertarcayrhttps://github.com/NixOS/nixpkgs/pull/530173 2.4.67 -> 2.4.68. killed my prev patch. also adds me back to maintainers.nix because nobody else is maintaining apache.01:55:05
@hugo:okeso.euHugo joined the room.13:42:05
@tgerbet:matrix.orgtgerbetI already had opened https://github.com/NixOS/nixpkgs/pull/529675 but let's go with your if you had yourself as the maintainer :) (Also please it's helpful if PRs with security fixes have the security label + the backport labels)18:23:34
11 Jun 2026
@arcayr:mischief.expertarcayrdon't think i could label stuff until now, i tried previously to tag something else as security and couldn't.02:30:37
@arcayr:mischief.expertarcayrguessing it's because i wasn't in the org.02:30:41
@arcayr:mischief.expertarcayrprevious apache patch actually is what i tried to tag02:30:56
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/53060005:25:52
@markus.theil:factory.secunet.comMarkus TheilYes, will do this evening. Sorry, somehow overlooked this.09:06:10
@hexa:lossy.networkhexa sterni https://kb.cert.org/vuls/id/862559 18:42:38
@hexa:lossy.networkhexaRedacted or Malformed Event18:42:45
@lav:xmr.selav joined the room.23:50:44
12 Jun 2026
@opandddd:matrix.orgSapii/Saperson changed their display name from Sapii to Sapii/Saperson.01:24:28
@markus.theil:factory.secunet.comMarkus TheilOpenSSL PR: https://github.com/NixOS/nixpkgs/pull/530955 I'm still doing some small smoke tests, like building systemd with it. Will mark as ready when done and ping here.07:22:26
@markus.theil:factory.secunet.comMarkus Theilhttps://github.com/NixOS/nixpkgs/pull/53096407:45:21
@markus.theil:factory.secunet.comMarkus Theil Added another PR for fast path, as mentioned by vcunat. 07:45:43
@robert:funklause.dedotlambdaI don't have time to look into whether https://github.com/NixOS/nixpkgs/pull/526853 can be backported. Note that https://github.com/NixOS/nixpkgs/pull/529580 fixes even more CVEs.18:51:11

Show newer messages


Back to Room ListRoom Version: 6