| 21 Jan 2026 |
hexa | https://seclists.org/oss-sec/2026/q1/98 bind9 | 16:34:03 |
ma27 | another one for glibc: https://www.openwall.com/lists/oss-security/2026/01/20/3
will do the patching tomorrow, off to bed now. | 22:19:43 |
ma27 |
There is no known application impact for this CVE, and the feature is generally non-functional with the two flags.
doesn't seem too bad anyways
(from https://sourceware.org/bugzilla/show_bug.cgi?id=33814) | 22:21:09 |
tgerbet | https://github.com/NixOS/nixpkgs/pull/482464 | 23:12:35 |
| 24 Jan 2026 |
leona | https://www.openwall.com/lists/oss-security/2026/01/23/8 cpython hexa | 20:34:08 |
hexa | I'm aware, was contemplating waiting for a release, because all were medium | 20:34:40 |
hexa | per https://peps.python.org/pep-0719/ that would be Feb 3rd | 20:36:07 |
hexa | same for 3.14 per https://peps.python.org/pep-0745/ | 20:36:41 |
vcunat | It would be nice to get a review on libxml2 patching:
https://github.com/NixOS/nixpkgs/pull/480844 | 20:45:20 |
vcunat | So that we can pull this stdenv rebuild into staging-next-25.11 soon. | 20:45:48 |
| 25 Jan 2026 |
| @cve:entropia.de left the room. | 16:11:42 |
| @hedgemage:unredacted.org left the room. | 19:11:47 |
| dadada changed their profile picture. | 20:33:59 |
| dadada changed their profile picture. | 20:39:02 |
| dadada changed their profile picture. | 21:17:38 |
| 27 Jan 2026 |
| whispers [& it/fae] changed their display name from whispers (it/fae) to whispers [& it/fae]. | 02:51:44 |
SigmaSquadron | XSAs #477 and #479: https://github.com/NixOS/nixpkgs/pull/484370 | 12:09:22 |
tgerbet | GnuPG with possible RCE
https://www.openwall.com/lists/oss-security/2026/01/27/8 | 17:47:11 |
tgerbet | Same for OpenSSL
https://www.openwall.com/lists/oss-security/2026/01/27/5 | 17:49:08 |
tgerbet | The possible RCE does not impact the 2.4.x branch we are using apparently | 17:53:11 |
vcunat | I'll update it. | 18:27:10 |
vcunat | https://github.com/NixOS/nixpkgs/pull/484463 | 18:28:37 |
| 28 Jan 2026 |
vcunat | Older openssl branch:
https://github.com/NixOS/nixpkgs/pull/484641 | 07:37:03 |
| Nina Fromm joined the room. | 16:52:59 |
| 30 Jan 2026 |
osnyx (he/him) | The November grub2 security patches never made it into 25.11, only master and 25.05. https://github.com/NixOS/nixpkgs/pull/485292 | 11:10:48 |
hexa | tgif, @K900 can you merge that with the kernel bumps? | 12:44:04 |
vcunat | I rebased it to staging-next-25.11 which should merge within a week. | 12:48:08 |
vcunat | (hopefully 4-5 days if we don't run into significant regressions) | 12:48:52 |
vcunat | * I rebased it to staging-next-25.11 which should merge to release-25.11 within a week. | 12:49:14 |
vcunat | * (hopefully in 4-5 days if we don't run into significant regressions) | 12:49:20 |