!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

730 Members
Coordination and triage of security issues in nixpkgs228 Servers

Load older messages


SenderMessageTime
7 May 2026
@hexa:lossy.networkhexahttps://github.com/V4bel/dirtyfrag19:57:24
@steinbes04:matrix.spline.desteinbes04 joined the room.20:07:55
@netali:cuties.devJennySeems to be related, but exploits other kernel modules: https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo21:58:29
@raitobezarius:matrix.orgraitobezariusIt's the same root cause21:59:32
@kybe:kybe.xyzkybe joined the room.22:04:14
@kuflierl:matrix.orgkuflierl https://github.com/NixOS/nixpkgs/pull/517642
Pretty old stuff I just forgot about because the bot didn't notify me
23:13:39
8 May 2026
@jopejoe1:matrix.orgjopejoe1 changed their display name from jopejoe1 (4094@epvpn) to jopejoe1.08:44:11
@k900:0upti.meK900https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.20614:49:02
@k900:0upti.meK9005.15 fix was wrong14:49:06
@k900:0upti.meK9006.1 also just got a respin15:20:45
@magic_rb:matrix.redalder.orgmagic_rb This patching round is going swimmingly 15:37:19
@pyrox:pyrox.devdish [Fox/It/She] https://ze3tar.github.io/post-zcrx.html 21:40:40
@pyrox:pyrox.devdish [Fox/It/She]sigh21:40:41
@pyrox:pyrox.devdish [Fox/It/She]tl;dr io_uring ZCRX freelist LPE21:40:50
@pyrox:pyrox.devdish [Fox/It/She]* tl;dr io_uring ZCRX freelist LPE, affects 6.15 -> 6.1921:41:13
@pyrox:pyrox.devdish [Fox/It/She]but also requires CAP_NET_ADMIN so shouldn't be too much of an issue21:41:34
@pyrox:pyrox.devdish [Fox/It/She] * but also requires CAP_NET_ADMIN and a NIC that supports zero copy recieve(ZCRX) so shouldn't be too much of an issue 21:42:03
@pyrox:pyrox.devdish [Fox/It/She] * but also requires CAP_NET_ADMIN, a NIC that supports zero copy recieve(ZCRX), and kernel configured with io_uring zcrx enabled so shouldn't be too much of an issue 21:42:30
@numinit:matrix.orgMorgan (@numinit)Nice, io_uring, the source of like over half of Android bug bounties over the past couple years21:42:59
@pyrox:pyrox.devdish [Fox/It/She] okay i think this is pretty much a nonissue since you need all the above to write OOB, but then CAP_SYS_ADMIN to execute so... seems like you basically need root and/or elevated privs so... 21:43:54
@numinit:matrix.orgMorgan (@numinit)

https://security.googleblog.com/2023/06/learnings-from-kctf-vrps-42-linux.html

Wish there was a dumpster fire emoji anyway

21:44:55
@pyrox:pyrox.devdish [Fox/It/She] πŸ”₯ πŸ—‘οΈ 21:46:25
@numinit:matrix.orgMorgan (@numinit)

"we paid out around 1 million USD for io_uring alone"

πŸ’ΈπŸ”₯

21:47:06
@sandro:supersandro.deSandroOne of the oauth2-proxy CVEs was only partically addressed and one of the recommended arguments to set was impossible to be defined https://github.com/NixOS/nixpkgs/pull/51821123:16:07
@sandro:supersandro.deSandro* One of the oauth2-proxy CVEs was only partically addressed and one of the recommended arguments to set was impossible to be defined in the nixos module https://github.com/NixOS/nixpkgs/pull/51821123:17:56
9 May 2026
@pyrox:pyrox.devdish [Fox/It/She] Gitpython security bump: https://github.com/NixOS/nixpkgs/pull/518443 17:20:00
11 May 2026
@kuflierl:matrix.orgkuflierl'high' severtiy cve in python library https://github.com/NixOS/nixpkgs/pull/51879802:28:11
@tgerbet:matrix.orgtgerbetDNSMasq coordinated release (cache poisoning, privesc...) https://www.kb.cert.org/vuls/id/471747 https://github.com/NixOS/nixpkgs/pull/51908217:34:09
@hexa:lossy.networkhexa

dnsmasq has released version 2.93 to fix the above vulnerabilities

17:36:23
@hexa:lossy.networkhexa

dnsmasq: 2.92 -> 2.92rel2

17:36:33

Show newer messages


Back to Room ListRoom Version: 6