30 Jun 2025 |
h0nig2k | * python setuptools CVE 7.7 (only 25.05): https://github.com/NixOS/nixpkgs/pull/421350 | 21:48:50 |
1 Jul 2025 |
| djacu joined the room. | 03:29:06 |
djacu | Hey Security Team
In case you haven't seen the recent post on discourse, the Marketing Team is preparing this year's community survey. I am reaching out to teams to see if there are any questions they would like to add to the survey to better serve the work you all do. More details in the post linked below.
https://discourse.nixos.org/t/community-feedback-requested-2025-nix-community-survey-planning/66155 | 03:29:17 |
| Pratham Patel changed their display name from Pratham Patel (you can mention me) to Pratham Patel. | 05:10:22 |
hexa | https://openssl-library.org/news/secadv/20250522.txt Markus Theil | 12:17:09 |
Markus Theil | Thx for the hint. Will add a PR this evening. | 13:57:22 |
Markus Theil | All mentioned CVEs are also fixed in the PR for 3.5.0 already merged to staging. Currently used version 3.4.x are not affected. | 13:58:26 |
SigmaSquadron | XSA #470: https://github.com/NixOS/nixpkgs/pull/421514 | 14:19:12 |
SigmaSquadron | * XSA #470: https://github.com/NixOS/nixpkgs/pull/421514 | 14:19:50 |
emily | on it. does it need backporting? | 14:39:36 |
| zororg joined the room. | 14:55:33 |
Markus Theil | https://github.com/NixOS/nixpkgs/pull/421531 is still compiling on my side. Will ping here, when ready and some smoke tests are done. | 15:33:21 |
SigmaSquadron | In reply to @emilazy:matrix.org on it. does it need backporting? yep, forgot the label, sorry. | 15:57:16 |
| Damian Poddebniak joined the room. | 20:54:51 |
2 Jul 2025 |
Markus Theil | OpenSSL is ready. Update for 25.05 in https://github.com/NixOS/nixpkgs/pull/421735 | 09:43:52 |
4 Jul 2025 |
Grimmauld (any/all) | https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572 https://nvd.nist.gov/vuln/detail/CVE-2025-6816 | https://github.com/HDFGroup/hdf5/issues/5571 https://nvd.nist.gov/vuln/detail/CVE-2025-6750 | https://github.com/HDFGroup/hdf5/issues/5549
hdf5 doesn't have a new release, and none of these CVEs have patches yet either. I'll be watching the issues, i have my own projects that depend on hdf5 (bachelors thesis) but figured i might as well post these here too. Fix will likely only come out in September.
| 07:53:03 |
Grimmauld (any/all) | * https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572 https://nvd.nist.gov/vuln/detail/CVE-2025-6816 | https://github.com/HDFGroup/hdf5/issues/5571 https://nvd.nist.gov/vuln/detail/CVE-2025-6750 | https://github.com/HDFGroup/hdf5/issues/5549 https://nvd.nist.gov/vuln/detail/CVE-2025-6516 | https://github.com/HDFGroup/hdf5/issues/5581
hdf5 doesn't have a new release, and none of these CVEs have patches yet either. I'll be watching the issues, i have my own projects that depend on hdf5 (bachelors thesis) but figured i might as well post these here too. Fix will likely only come out in September.
| 07:54:17 |
Grimmauld (any/all) | * https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572 https://nvd.nist.gov/vuln/detail/CVE-2025-6816 | https://github.com/HDFGroup/hdf5/issues/5571 https://nvd.nist.gov/vuln/detail/CVE-2025-6750 | https://github.com/HDFGroup/hdf5/issues/5549 https://nvd.nist.gov/vuln/detail/CVE-2025-6516 | https://github.com/HDFGroup/hdf5/issues/5581 https://nvd.nist.gov/vuln/detail/CVE-2025-6270 | https://github.com/HDFGroup/hdf5/issues/5580 https://nvd.nist.gov/vuln/detail/CVE-2025-6269 | https://nvd.nist.gov/vuln/detail/CVE-2025-6269
hdf5 doesn't have a new release, and none of these CVEs have patches yet either. I'll be watching the issues, i have my own projects that depend on hdf5 (bachelors thesis) but figured i might as well post these here too. Fix will likely only come out in September.
| 07:55:50 |
Grimmauld (any/all) | there might well be more, seems some new people started actually fuzzing that lib. There is POCs and all, but assigned severity is all somewhat low. Still safe to say the next release is security-relevant | 07:57:13 |
Grimmauld (any/all) | * https://nvd.nist.gov/vuln/detail/CVE-2025-6817 | https://github.com/HDFGroup/hdf5/issues/5572 https://nvd.nist.gov/vuln/detail/CVE-2025-6816 | https://github.com/HDFGroup/hdf5/issues/5571 https://nvd.nist.gov/vuln/detail/CVE-2025-6750 | https://github.com/HDFGroup/hdf5/issues/5549 https://nvd.nist.gov/vuln/detail/CVE-2025-6516 | https://github.com/HDFGroup/hdf5/issues/5581 https://nvd.nist.gov/vuln/detail/CVE-2025-6270 | https://github.com/HDFGroup/hdf5/issues/5580 https://nvd.nist.gov/vuln/detail/CVE-2025-6269 | https://github.com/HDFGroup/hdf5/issues/5579
hdf5 doesn't have a new release, and none of these CVEs have patches yet either. I'll be watching the issues, i have my own projects that depend on hdf5 (bachelors thesis) but figured i might as well post these here too. Fix will likely only come out in September.
| 08:00:54 |
Grimmauld (any/all) | assimp: https://github.com/NixOS/nixpkgs/pull/422357
CVE-2025-2751: GHSA-345v-qrhv-w227
CVE-2025-2757: GHSA-4p6w-747g-444c
CVE-2025-2750: GHSA-6x45-4j6r-r8x8
CVE-2025-3158: GHSA-6r79-vpvw-rfjj | 10:42:06 |
K900 |  Download image.png | 10:42:56 |
emily | K900: oh yeah I ran into a fun thing | 11:06:15 |
emily | er | 11:06:24 |
emily | wrong room sorry | 11:06:26 |
6 Jul 2025 |
| @jammie:matrix.org left the room. | 02:28:02 |
| Cathal changed their display name from CJ to Cathal. | 17:17:33 |
7 Jul 2025 |
leona | https://github.com/NixOS/nixpkgs/pull/421805 keycloak security update | 06:51:59 |
| Katalin 🔪 changed their display name from Katalin ⚧︎ to Katalin 🔪. | 23:27:41 |
9 Jul 2025 |
| jonhermansen joined the room. | 01:01:41 |