!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

702 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
25 Mar 2026
@qyliss:fairydust.spaceAlyssa RossPresumably mainline will have the patch at some point?06:37:24
@qyliss:fairydust.spaceAlyssa Rossbut maybe we should ask…06:41:23
@sigmasquadron:matrix.orgFernando Rodriguesit will; this would be about patching ahead of schedule. We do that for Xen since minor version bumps take forever to release, but I'm not sure how we do things in the kernel.06:56:21
@qyliss:fairydust.spaceAlyssa Rossstable kernels are weekly, but this patch has not even been posted to a kernel list yet06:58:51
@qyliss:fairydust.spaceAlyssa Rossah but it was committed directly to Linus's tree, good07:01:17
@qyliss:fairydust.spaceAlyssa Rossso generally it will be in 7.0-rc6 on Sunday, and then stable kernels the following Friday.07:01:55
@qyliss:fairydust.spaceAlyssa Rossbut in this case, I already see them in the stable kernel queue, so they're likely to make it into this Friday's instead07:04:21
@sigmasquadron:matrix.orgFernando Rodriguesawesome07:42:27
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/38314:45:37
@hexa:lossy.networkhexabackdoor in litellm 1.82.714:45:43
@hexa:lossy.networkhexaRedacted or Malformed Event14:46:19
@hexa:lossy.networkhexaok, master has 1.81.1414:46:28
@kirillrdy:matrix.orgkirillrdyit only affects artifacts on pypi, nixpkgs fetches from github19:24:05
@benjaminsparks:chat.alugha.appBen Sparksas long as no one has the bright idea to bump nixpkgs to a revision on pypi :)19:34:55
@benjaminsparks:chat.alugha.appBen Sparks* as long as no one has the bright idea to bump nixpkgs to said revision on pypi :)19:35:07
@kirillrdy:matrix.orgkirillrdyits already been yanked from pypi19:36:55
26 Mar 2026
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/387 libpng00:48:39
@hexa:lossy.networkhexaRedacted or Malformed Event00:48:43
@vcunat:matrix.orgvcunat It's a huge rebuild, so there's at least one week of time (before starting another staging-next*) 10:00:27
@vcunat:matrix.orgvcunat Unless we'd like to scrap the few days of the current staging-next-25.11. (as this one looks potentially quite serious) 10:01:13
@vcunat:matrix.orgvcunat * Unless we'd like to scrap the few days of the current staging-next-25.11. (as this one looks potentially quite serious; see the first Impact: section) 10:02:23
@meadow_weasel:matrix.org@meadow_weasel:matrix.org left the room.15:04:56
@ma27:nicht-so.sexyma27 glibc security update: https://github.com/NixOS/nixpkgs/pull/503779 16:40:27
@ma27:nicht-so.sexyma27also checking if 25.11 is affected (I think so). can I target -next-25.11 oder rather staging?16:41:01
@vcunat:matrix.orgvcunat-linux is over 40% rebuilt in there, so unless it's critical...17:11:44
@vcunat:matrix.orgvcunat * -linux is over 40% rebuilt in there, so unless it's critical, I'd choose staging-25.11. 17:12:00
@vcunat:matrix.orgvcunat * -linux is over 40% rebuilt in there, so unless it's really urgent, I'd choose staging-25.11. 17:12:14
@vcunat:matrix.orgvcunatThe description doesn't sound serious to me, at a quick read: https://sourceware.org/bugzilla/show_bug.cgi?id=34014#c017:15:27
@ma27:nicht-so.sexyma27agreed. it's also not even on the 2.40 release branch 🤷17:17:33
@vcunat:matrix.orgvcunatI honestly don't get it. A prerequisite is that your configured DNS resolver is malicious. And the impact is that answer returned by that resolver is interpreted incorrectly? I guess I'm too tired today?17:17:46

Show newer messages


Back to Room ListRoom Version: 6