!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

702 Members
Coordination and triage of security issues in nixpkgs216 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
22 Mar 2024
@bumperboat:matrix.org@bumperboat:matrix.org changed their display name from bumperboat (UTC+8 when) to bumperboat (UTC+8).15:02:10
@felschr:matrix.orgfelschr

https://github.com/NixOS/nixpkgs/pull/298196

This is an unscheduled emergency release with important security updates to Firefox for Desktop platforms.

23:14:01
23 Mar 2024
@ss:someonex.netSomeoneSerge (matrix works sometimes) changed their display name from SomeoneSerge (hash-versioned python modules when) to SomeoneSerge (migrating synapse).02:11:06
@felschr:matrix.orgfelschr *

https://github.com/NixOS/nixpkgs/pull/298196
https://github.com/NixOS/nixpkgs/pull/298202

This is an unscheduled emergency release with important security updates to Firefox for Desktop platforms.

10:50:21
24 Mar 2024
@hexa:lossy.networkhexahttps://gnutls.org/security-new.html#GNUTLS-SA-2023-12-0411:05:08
@hexa:lossy.networkhexa * https://gnutls.org/security-new.html#GNUTLS-SA-2023-12-04 vcunat 11:07:44
@tgerbet:matrix.orgtgerbetUnstable here https://github.com/NixOS/nixpkgs/pull/297657 Taking a look for the backport to stable, looks like the file has been nixpkgs-fmted11:12:44
@hexa:lossy.networkhexaah thanks, for some reason I missed it when I checked the version on staging11:17:38
@tgerbet:matrix.orgtgerbethttps://github.com/NixOS/nixpkgs/pull/29860411:19:29
@qyliss:fairydust.spaceAlyssa RossSeems to regress musl :(14:31:41
25 Mar 2024
@binarycat:snug.moeネコ joined the room.00:12:11
@binarycat:snug.moeネコhey i found a way to put nulls in strings, unsure if that has security implications, but it should probably be an error?00:14:04
@binarycat:snug.moeネコunsure if i should open an issue on github? could this be used for some sort of buffer overflow attack? idk00:15:48
@admin:nixos.org@admin:nixos.org joined the room.00:23:10
@hexa:lossy.networkhexa can you explain more in #security-discuss:nixos.org 00:23:58
@hexa:lossy.networkhexa * can you explain more in #security-discuss:nixos.org? 00:24:04
@admin:nixos.org@admin:nixos.org left the room.00:30:35
@r_i_s:matrix.orgris_https://github.com/NixOS/nixpkgs/pull/29754720:14:15
@hexa:lossy.networkhexawow, this looks like code copy pasted from home-assistant 😄 20:30:09
@hexa:lossy.networkhexawhich can be explained because bdraco was involved20:30:32
26 Mar 2024
@hexa:lossy.networkhexa https://webkitgtk.org/security/WSA-2024-0002.html Jan Tojnar 03:22:18
@linucifer:envs.net@linucifer:envs.net joined the room.19:09:13
@pinpox:matrix.orgpinpoxNot sure if this is the right place to ask, but are current NixOS versions impacted by https://github.com/Notselwyn/CVE-2024-1086 ? 20:33:53
@k900:0upti.meK900Mo20:34:38
@k900:0upti.meK900* No20:34:45
@k900:0upti.meK900

The exploit affects versions from (including) v5.14 to (including) v6.6, excluding patched branches v5.15.149>, v6.1.76>, v6.6.15>

20:35:11

Show newer messages


Back to Room ListRoom Version: 6