!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

701 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
1 Mar 2026
@errornointernet:envs.net@errornointernet:envs.net removed their profile picture.11:40:28
@errornointernet:envs.net@errornointernet:envs.net removed their display name ErrorNoInternet.11:41:08
@errornointernet:envs.net@errornointernet:envs.net left the room.11:41:50
@flandweber:envs.net@flandweber:envs.net removed their display name Finn Landweber.12:17:14
@flandweber:envs.net@flandweber:envs.net left the room.12:17:18
@winston:winston.shwinston joined the room.16:56:27
2 Mar 2026
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.12:51:19
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.13:08:23
@walrusred_foxvapor00314:matrix.org~centipede♡ joined the room.20:39:08
3 Mar 2026
@genericnerdyusername:matrix.org@genericnerdyusername:matrix.org left the room.00:18:30
@hexa:lossy.networkhexahttps://seclists.org/oss-sec/2026/q1/253 freetype ttuegel22:47:16
4 Mar 2026
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.03:13:11
@os:matrix.flyingcircus.ioosnyx (he/him)https://github.com/NixOS/nixpkgs/pull/495788 As promised: actually install updated grub packages.09:55:51
5 Mar 2026
@mtheil:scs.ems.hostMarkus Theil (SCS) changed their display name from Markus Theil to Markus Theil (SCS).09:33:45
@markus.theil:factory.secunet.comMarkus Theil joined the room.12:03:01
@hexa:lossy.networkhexa @stigo various cpan security things on oss-security
  1. https://www.openwall.com/lists/oss-security/2026/03/05/5 Compress::Raw::Zlib

  2. https://www.openwall.com/lists/oss-security/2026/03/05/4 UnQLite

  3. https://www.openwall.com/lists/oss-security/2026/03/05/3 Apache:Session::Generate::MD5

  4. https://www.openwall.com/lists/oss-security/2026/03/05/2 Plack::Middleware::Session::Simple

  5. https://www.openwall.com/lists/oss-security/2026/03/05/1 Net::NSCA::Client


anything for us?
18:13:29
@hexa:lossy.networkhexa @stigo 18:14:59
@hexa:lossy.networkhexa Various cpan security things on oss-security
  1. https://www.openwall.com/lists/oss-security/2026/03/05/5 Compress::Raw::Zlib

  2. https://www.openwall.com/lists/oss-security/2026/03/05/4 UnQLite

  3. https://www.openwall.com/lists/oss-security/2026/03/05/3 Apache:Session::Generate::MD5

  4. https://www.openwall.com/lists/oss-security/2026/03/05/2 Plack::Middleware::Session::Simple

  5. https://www.openwall.com/lists/oss-security/2026/03/05/1 Net::NSCA::Client


anything for us?
18:15:12
@stigo:matrix.orgstigo Only Apache::Session (but no fix is available upstream), our Compress::Raw::Zlib is not affected since we use pkgs.zlib and not the vendored one. 18:57:46
6 Mar 2026
@benjaminsparks:chat.alugha.appBen Sparks joined the room.15:57:52
@ctheune:matrix.flyingcircus.ioTheuni changed their display name from Christian Theune to Theuni.19:57:26
8 Mar 2026
@robert:funklause.dedotlambdahttps://github.com/NixOS/nixpkgs/pull/497748 Not sure what to do about release-25.11 because the upstream patch doesn't apply cleanly there.00:50:24
@robert:funklause.dedotlambda* https://github.com/NixOS/nixpkgs/pull/497748 Not sure what to do about release-25.11 because the upstream patch (https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=patch;h=f36bd900a899088ca1925de079bd58d6205a1f3c) doesn't apply cleanly there.00:51:28
@hexa:lossy.networkhexa
12 files changed, 552 insertions(+), 23 deletions(-)
01:04:07
@hexa:lossy.networkhexayikes01:04:08
@hexa:lossy.networkhexathen maybe try a full backport?01:05:34
@hexa:lossy.networkhexaor try to check if other distros have a rebased version of the patch01:06:51
19 May 2021
@grahamc:nixos.org@grahamc:nixos.org set the history visibility to "world_readable".22:57:54
@grahamc:nixos.org@grahamc:nixos.org changed the room name to "" from "".22:57:54
@andreas.schraegle:helsinki-systems.deajs124 joined the room.22:58:46

Show newer messages


Back to Room ListRoom Version: 6