!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

676 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22211 Servers

Load older messages


SenderMessageTime
10 Sep 2024
@hexa:lossy.networkhexahttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-2024091018:36:19
11 Sep 2024
@hexa:lossy.networkhexahttps://curl.se/docs/CVE-2024-8096.html12:35:28
@hexa:lossy.networkhexa * https://curl.se/docs/CVE-2024-8096.html curl w/ gnutls12:35:50
@k900:0upti.meK900Steam no longer affected :P12:36:18
@niko:conduit.rsnyanbinary left the room.15:29:00
13 Sep 2024
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] (expect delays in answers) to tlaurion aka Insurgo [UTC-4] (expect long delays in answers).03:45:37
@cafkafk:gitter.imcafkafkis this known https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/, can't find any pr/issue on it, and as far as I can tell gitlab and gitlab-ee is affected05:39:49
@cafkafk:gitter.imcafkafk * is this known https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/, can't find any pr/issue on it, and as far as I can tell gitlab and gitlab-ee is affected (nvm, found https://github.com/NixOS/nixpkgs/pull/341398, I'm just blind)06:01:10
@aidalgol:matrix.orgaidalgol
In reply to @k900:0upti.me
Steam no longer affected :P
Because of the recent PR that removed a ton of optional dependencies, or something else?
20:06:56
@k900:0upti.meK900
In reply to @aidalgol:matrix.org
Because of the recent PR that removed a ton of optional dependencies, or something else?
Because of another recent PR replacing curlWithGnuTls with just curl
20:21:53
14 Sep 2024
@ss:someonex.netSomeoneSerge (back on matrix) changed their display name from SomeoneSerge (nix.camp) to SomeoneSerge (utc+3).11:38:19
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] (expect long delays in answers) to tlaurion aka Insurgo [UTC-4] (🛫🗺️🛬: Back 2024-10-01)).19:38:51
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from tlaurion aka Insurgo [UTC-4] (🛫🗺️🛬: Back 2024-10-01)) to tlaurion aka Insurgo [UTC-4] (🛫🗺️🛬: Back 2024-10-01).19:40:33
15 Sep 2024
@amythegay:161.rocks@amythegay:161.rocks changed their display name from amy to amy (Old).10:04:42
@amythegay:161.rocks@amythegay:161.rocks left the room.14:22:36
16 Sep 2024
@silentlurker:matrix.orgsilentlurker joined the room.20:00:41
@alisonjenkins:matrix.orgAlison Jenkins set a profile picture.20:21:01
@alisonjenkins:matrix.orgAlison Jenkins changed their profile picture.20:21:09
17 Sep 2024
@lassulus:lassul.uslassulus changed their profile picture.14:38:28
@tomherbers:matrix.orgTom (deprecated) joined the room.21:04:04
18 Sep 2024
@yaya:uwu.isyaya GitLab is open again, I'm on it. 10:15:32
@yaya:uwu.isyaya *

GitLab is open again, I'm on it.

EDIT: Opened #342765

10:42:33
@fabianhjr:matrix.orgFabián Herediahttps://www.tenable.com/cve/CVE-2024-40896 Critical CVSSv3 of 9.7 on libxml2 https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 Currently reserved in MITRE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40896 https://github.com/NixOS/nixpkgs/pull/34289522:41:48
@fabianhjr:matrix.orgFabián HerediaScored as Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H According to the first link22:42:37
@fabianhjr:matrix.orgFabián HerediaSeems not as critital, mentions that it depends on very specific usage of the library by downstream code22:59:24
19 Sep 2024
@adam:robins.wtfadamcstephensenvoy is publishing a series of security updates for all their supported releases. i'm starting on 1.30.6 which is in 24.05. i assume they'll publish a 1.31.2 which would be needed for unstable https://github.com/envoyproxy/envoy/releases/tag/v1.30.621:00:16
@adam:robins.wtfadamcstephens I'll probably be out when the 1.31 release drops, but will get to it later this evening if lukegb (he/him) hasn't 21:06:52
21 Sep 2024
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.18:21:42
22 Sep 2024
@rootname:matrix.org@rootname:matrix.org left the room.10:56:38
@implr:hackerspace.plimplr left the room.18:28:59

Show newer messages


Back to Room ListRoom Version: 6