!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

672 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22206 Servers

Load older messages


SenderMessageTime
25 Mar 2026
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/38314:45:37
@hexa:lossy.networkhexabackdoor in litellm 1.82.714:45:43
@hexa:lossy.networkhexaRedacted or Malformed Event14:46:19
@hexa:lossy.networkhexaok, master has 1.81.1414:46:28
@kirillrdy:matrix.orgkirillrdyit only affects artifacts on pypi, nixpkgs fetches from github19:24:05
@benjaminsparks:chat.alugha.appBen Sparksas long as no one has the bright idea to bump nixpkgs to a revision on pypi :)19:34:55
@benjaminsparks:chat.alugha.appBen Sparks* as long as no one has the bright idea to bump nixpkgs to said revision on pypi :)19:35:07
@kirillrdy:matrix.orgkirillrdyits already been yanked from pypi19:36:55
26 Mar 2026
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/387 libpng00:48:39
@hexa:lossy.networkhexaRedacted or Malformed Event00:48:43
@vcunat:matrix.orgvcunat It's a huge rebuild, so there's at least one week of time (before starting another staging-next*) 10:00:27
@vcunat:matrix.orgvcunat Unless we'd like to scrap the few days of the current staging-next-25.11. (as this one looks potentially quite serious) 10:01:13
@vcunat:matrix.orgvcunat * Unless we'd like to scrap the few days of the current staging-next-25.11. (as this one looks potentially quite serious; see the first Impact: section) 10:02:23
@meadow_weasel:matrix.org@meadow_weasel:matrix.org left the room.15:04:56
@ma27:nicht-so.sexyma27 glibc security update: https://github.com/NixOS/nixpkgs/pull/503779 16:40:27
@ma27:nicht-so.sexyma27also checking if 25.11 is affected (I think so). can I target -next-25.11 oder rather staging?16:41:01
@vcunat:matrix.orgvcunat-linux is over 40% rebuilt in there, so unless it's critical...17:11:44
@vcunat:matrix.orgvcunat * -linux is over 40% rebuilt in there, so unless it's critical, I'd choose staging-25.11. 17:12:00
@vcunat:matrix.orgvcunat * -linux is over 40% rebuilt in there, so unless it's really urgent, I'd choose staging-25.11. 17:12:14
@vcunat:matrix.orgvcunatThe description doesn't sound serious to me, at a quick read: https://sourceware.org/bugzilla/show_bug.cgi?id=34014#c017:15:27
@ma27:nicht-so.sexyma27agreed. it's also not even on the 2.40 release branch 🤷17:17:33
@vcunat:matrix.orgvcunatI honestly don't get it. A prerequisite is that your configured DNS resolver is malicious. And the impact is that answer returned by that resolver is interpreted incorrectly? I guess I'm too tired today?17:17:46
27 Mar 2026
@pyrox:pyrox.devdish [Fox/It/She] manual backport of the last 3 nats-server releases to fix a few security issues for it on release-25.11 https://github.com/NixOS/nixpkgs/pull/503952 04:52:26
@pyrox:pyrox.devdish [Fox/It/She](by a few, I mean a lot, there's over 10 issues open from sectracker rn)04:52:50
@pyrox:pyrox.devdish [Fox/It/She]none of the open issues affect master branch since it's on the latest release that has fixes for all known issues that are on nixpkgs' security tracker04:55:16
@vcunat:matrix.orgvcunatI'd say it has security aspects, but no idea about severity: https://github.com/NixOS/nixpkgs/pull/50386906:20:31
@ma27:nicht-so.sexyma27 grafana security updates: https://github.com/NixOS/nixpkgs/pull/504009, https://github.com/NixOS/nixpkgs/pull/504014 (25.11) 10:33:43
@sasha:the-apothecary.clubMoved to @sashanoraa:matrix.org changed their display name from Sashanoraa.gay (she/her, ze/zir) to Moved to @sashanoraa:matrix.org.15:27:45

There are no newer messages yet.


Back to Room ListRoom Version: 6