!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

717 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22222 Servers

Load older messages


SenderMessageTime
11 Jun 2026
@hexa:lossy.networkhexaRedacted or Malformed Event18:42:45
@lav:xmr.selav joined the room.23:50:44
12 Jun 2026
@opandddd:matrix.orgSapii/Saperson changed their display name from Sapii to Sapii/Saperson.01:24:28
@markus.theil:factory.secunet.comMarkus TheilOpenSSL PR: https://github.com/NixOS/nixpkgs/pull/530955 I'm still doing some small smoke tests, like building systemd with it. Will mark as ready when done and ping here.07:22:26
@markus.theil:factory.secunet.comMarkus Theilhttps://github.com/NixOS/nixpkgs/pull/53096407:45:21
@markus.theil:factory.secunet.comMarkus Theil Added another PR for fast path, as mentioned by vcunat. 07:45:43
@robert:funklause.dedotlambdaI don't have time to look into whether https://github.com/NixOS/nixpkgs/pull/526853 can be backported. Note that https://github.com/NixOS/nixpkgs/pull/529580 fixes even more CVEs.18:51:11
14 Jun 2026
@aangularframework:matrix.org@aangularframework:matrix.org left the room.15:49:02
@nick-linux8:mozilla.orgNick joined the room.16:20:16
@nick-linux8:mozilla.orgNickFixes critical CVE in perl package https://github.com/NixOS/nixpkgs/pull/53180923:22:54
@hexa:lossy.networkhexaperl maintainers have been requested23:45:14
15 Jun 2026
@stigo:matrix.orgstigoCritical is probably pushing it a bit, that CVSS score comes from CISA btw12:16:46
@tcllama:matrix.orgtcllama joined the room.18:39:14
17 Jun 2026
@k900:0upti.meK900 https://www.cve.org/CVERecord?id=CVE-2026-42530 nginx vuln just dropped 17:15:52
@hexa:lossy.networkhexah3 only17:17:25
@hexa:lossy.networkhexa1.30.x is not yet EOL17:18:28
@hexa:lossy.networkhexaso is it not vulnerable per https://my.f5.com/manage/s/article/K000161616?17:18:41
@hexa:lossy.networkhexa
Download
17:18:55
@r-burns:matrix.orgr-burns joined the room.19:14:06
@r-burns:matrix.orgr-burnsPR to address CVE-2026-12043 HIGH Heap double-free in AWS Common Runtime https://github.com/NixOS/nixpkgs/pull/531504 Messaging here because this is a dependency of Nix via its AWS support which is typically enabled by default. Not sure of the severity here, perhaps low because it's only a concern if fetching a path from a compromised S3 bucket? Or perhaps not a concern at all if Nix only calls out to aws-c-common at runtime, not the aws-c-http component (not sure). Just wanted to point it out here so someone more knowledgeable can triage appropriately.19:22:52
@numinit:matrix.orgMorgan (@numinit)

https://lore.kernel.org/util-linux/c2fo4x3lcppsj77k564i4qodmon3wagx47qf4mqwjwdtiplupg@jmaqrlzp273h/T/

On it in a couple hours, looks like libmount stuff

22:30:59
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)
In reply to @r-burns:matrix.org
PR to address CVE-2026-12043 HIGH Heap double-free in AWS Common Runtime https://github.com/NixOS/nixpkgs/pull/531504 Messaging here because this is a dependency of Nix via its AWS support which is typically enabled by default. Not sure of the severity here, perhaps low because it's only a concern if fetching a path from a compromised S3 bucket? Or perhaps not a concern at all if Nix only calls out to aws-c-common at runtime, not the aws-c-http component (not sure). Just wanted to point it out here so someone more knowledgeable can triage appropriately.
The http component usage should be quite limited? This presumably also affects the cpp sdk (used by older nix versions)? If not, the http client usage should be limited to doing auth and such – the actual download is done by libcurl
22:33:29
@r-burns:matrix.orgr-burnsIt looks like modern nix 2.34 still links against it, just via aws-crt-cpp instead of aws-sdk-cpp. But yes, it looks like the only usage of AWS libs in modern nix is now in libstore/aws-creds.cc, which only appears to be using aws-c-auth and aws-c-io functionality. So yeah Nix is probably unaffected then, thanks for clarifying :)22:59:47
18 Jun 2026
@stigo:matrix.orgstigoI'm looking at all outstanding perlPackages vuln patches today12:12:33
@r-burns:matrix.orgr-burns ^ maybe not fully accurate as aws-c-auth appears to call out to aws-c-http internally, but they're not interacted with directly by Nix, at least 13:39:22
@stigo:matrix.orgstigohttps://github.com/NixOS/nixpkgs/pull/533010 <-- several perlPackages17:12:21
@whispers:catgirl.cloudwhispers [& it/fae] changed their display name from whispers [& it/fae] to meow meow.18:46:29
@whispers:catgirl.cloudwhispers [& it/fae] changed their display name from meow meow to whispers [& it/fae].19:12:06
@heartfelt_heron:matrix.orgHeartfelt Heron joined the room.22:11:42
@sandro:supersandro.deSandro 🐧https://github.com/hedgedoc/hedgedoc/releases/tag/1.11.022:14:51

Show newer messages


Back to Room ListRoom Version: 6