gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
<gchristensen> marek: can you issue a backport PR with `git cherry-pick -x the-commits-hash` (in this case, a4e6261173a18d9e0cb2f02b73fb7fbae91ecaaf)
<gchristensen> on to release-19.03
<marek> gchristensen: from the CVE I understand only version 4.0.0 (which is unstable for us) is affected
<marek> gchristensen: https://nvd.nist.gov/vuln/detail/CVE-2019-12155#vulnCurrentDescriptionTitle can you check this just in case? I assumed they would mention "all versions" or "until 4.0.1"?
<marek> gchristensen: ok - that is not the case :) the file is there in 3.0.1 too, so I assumed it is affected as well PR done https://github.com/NixOS/nixpkgs/pull/63188
<{^_^}> #63188 (by mmahut, 18 seconds ago, open): qemu: CVE-2019-12155
<gchristensen> ah okay
Synthetica has joined #nixos-security
justanotheruser has quit [Quit: WeeChat 2.4]
justanotheruser has joined #nixos-security
tilpner has quit [Quit: WeeChat 2.4]
tilpner has joined #nixos-security
Synthetica has quit [Quit: Connection closed for inactivity]
justanotheruser has quit [Ping timeout: 245 seconds]
justanotheruser has joined #nixos-security