!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

719 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22221 Servers

Load older messages


SenderMessageTime
31 May 2026
@keysmashes:matrix.orgkeysmashes joined the room.12:02:24
@sersorrel:matrix.orgsorrel -> keysmashes changed their display name from sorrel to sorrel -> keysmashes.12:08:33
1 Jun 2026
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/52652914:35:36
2 Jun 2026
@kuflierl:matrix.orgkuflierlhttps://github.com/NixOS/nixpkgs/pull/52716414:51:37
@robert:funklause.dedotlambdaI'm not sure about https://github.com/NixOS/nixpkgs/pull/52451015:26:16
@robert:funklause.dedotlambdasame for https://github.com/NixOS/nixpkgs/pull/52450815:27:00
@robert:funklause.dedotlambdaand https://github.com/NixOS/nixpkgs/pull/52450715:27:32
@monokles:matrix.monokles.eumonokles joined the room.16:10:45
3 Jun 2026
@samuel.dionne-riel:cyberus-technology.deSamuel Dionne-Riel

the following PRs may need to be labeled with the security label:

  • https://github.com/NixOS/nixpkgs/pull/468076
  • https://github.com/NixOS/nixpkgs/pull/514056
  • https://github.com/NixOS/nixpkgs/pull/507810
21:06:44
4 Jun 2026
@jkarlson:kapsi.fiEmil Thorsøewow, openvpn has been marginally vulnerable since 2026-04-2203:46:53
@callmeecho:matrix.orgEcho changed their profile picture.04:23:41
@k900:0upti.meK900 libinput RCE-ish: https://gitlab.freedesktop.org/libinput/libinput/-/releases/1.31.3 06:54:31
@k900:0upti.meK900Will do a PR in a bit06:54:37
@k900:0upti.meK900 https://github.com/NixOS/nixpkgs/pull/527861 07:07:08
@k900:0upti.meK900 (don't merge yet, waiting for 26.05 backport for previous update) 07:07:34
@arias:arialocke.gayarias 🏳️‍⚧️ joined the room.21:50:55
5 Jun 2026
@stigo:matrix.orgstigo https://github.com/NixOS/nixpkgs/pull/528021 <- perl issues 10:46:52
@zimbatm:numtide.com@zimbatm:numtide.com left the room.11:40:58
6 Jun 2026
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q2/822 freetype01:20:35
@whispers:catgirl.cloudwhispers [& it/fae]^ attempt at https://github.com/NixOS/nixpkgs/pull/52865203:54:33
@jkarlson:kapsi.fiEmil ThorsøeCan you elaborate on RCE, I see local privilege escalation?04:24:23
@k900:0upti.meK900 I can't read 07:35:06
7 Jun 2026
@arcayr:mischief.expertarcayri think the apache team figure cve-2026-49975 isn't worth a proper release, so my pr with the debian patches for it is probably going to be it for a while02:31:14
@arcayr:mischief.expertarcayrare we okay to fetchpatch2 from debian directly or would it be preferred to host the patches02:31:25
@arcayr:mischief.expertarcayri originally hosted them but figured it looks a bit more reliable and legitimate if they're actually from debian, idk02:31:57
@arcayr:mischief.expertarcayr * 02:32:06
@arcayr:mischief.expertarcayr * 02:32:13
@hexa:lossy.networkhexafetchpatch is fine02:37:47
@vcunat:matrix.orgvcunatFrom Debian you probably fetchurl, as they have it as a *file* in git.05:56:37
9 Jun 2026
@hexa:lossy.networkhexa Markus Theil are you doing the openssl updates? and 4.0? 12:05:38

Show newer messages


Back to Room ListRoom Version: 6