!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

759 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
9 May 2026
@pyrox:pyrox.devdish [Fox/It/She] Gitpython security bump: https://github.com/NixOS/nixpkgs/pull/518443 17:20:00
11 May 2026
@kuflierl:matrix.orgkuflierl'high' severtiy cve in python library https://github.com/NixOS/nixpkgs/pull/51879802:28:11
@tgerbet:matrix.orgtgerbetDNSMasq coordinated release (cache poisoning, privesc...) https://www.kb.cert.org/vuls/id/471747 https://github.com/NixOS/nixpkgs/pull/51908217:34:09
@hexa:lossy.networkhexa

dnsmasq has released version 2.93 to fix the above vulnerabilities

17:36:23
@hexa:lossy.networkhexa

dnsmasq: 2.92 -> 2.92rel2

17:36:33
@hexa:lossy.networkhexahttps://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html17:37:29
@hexa:lossy.networkhexa

With luck, 2.93 could be out in a week or so.

17:37:33
@tgerbet:matrix.orgtgerbetRequested an update of the CERT/CC advisory in the internal case...17:40:14
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51843023:24:08
12 May 2026
@harinn:matrix.orgHarinn joined the room.18:14:40
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51950218:32:28
13 May 2026
@flx-:matrix.orgflxhttps://github.com/NixOS/nixpkgs/pull/51988219:12:05
@numinit:matrix.orgMorgan (@numinit)

https://depthfirst.com/nginx-rift

FYI, nginx 😬, seems to trigger with captures in rewrite

19:15:16
@tgerbet:matrix.orgtgerbethttps://nginx.org/en/CHANGES https://nginx.org/en/CHANGES-1.30 There are also other sec issues in the releases nginxMainline will need a 1.29 -> 1.31 bump. It would be nice if someone could handle it, I have done the last nginx upgrades but I'm not close to a laptop until tomorrow night19:23:09
@numinit:matrix.orgMorgan (@numinit)It's looking like a "tonight" thing for me (so several hours)19:23:44
@hexa:lossy.networkhexahttps://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/19:35:01
@hexa:lossy.networkhexa ma27 19:35:22
@sandro:supersandro.deSandrountested https://github.com/NixOS/nixpkgs/pull/51989319:46:05
@ma27:nicht-so.sexyma27tomorrow if noone's faster22:44:35
14 May 2026
@louis:opter.orglouis joined the room.23:21:54
@louis:opter.orglouis left the room.23:22:37
15 May 2026
@louis:opter.orglouis joined the room.04:50:18
@leona:leona.isleonaRedacted or Malformed Event06:59:27
@leona:leona.isleona https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/ was again pre-leaked (likely through commit msg + Spengler (as Qualys reported on oss-sec)). Qualys doesn't yet publish their advisory. 07:01:33
@leona:leona.isleona * https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn/ was again pre-leaked (likely through commit msg + LLM + Spengler (as Qualys reported on oss-sec)). Qualys doesn't yet publish their advisory. 07:01:41
@arcayr:mischief.expertarcayrspengler again?07:19:08
@bart:bartoostveen.nlBart https://github.com/NixOS/nixpkgs/pull/517598 12:03:38
@kuflierl:matrix.orgkuflierlhttps://github.com/NixOS/nixpkgs/pull/52064622:58:40
16 May 2026
@jwh4j4ez25q:matrix.orgmaurice joined the room.10:04:53
17 May 2026
@numinit:matrix.orgMorgan (@numinit)

BIND preannouncing that they are publishing a new release on May 20

https://lists.isc.org/pipermail/bind-announce/2026-May/001294.html

20:47:14

Show newer messages


Back to Room ListRoom Version: 6