gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
andi- has quit [Remote host closed the connection]
andi- has joined #nixos-security
Yakulu has joined #nixos-security
hmpffff has joined #nixos-security
hmpffff has quit [Client Quit]
hmpffff has joined #nixos-security
hmpffff has quit [Quit: nchrrrr…]
hmpffff has joined #nixos-security
hmpffff_ has joined #nixos-security
hmpffff_ has quit [Read error: Connection reset by peer]
hmpffff__ has joined #nixos-security
hmpffff has quit [Ping timeout: 258 seconds]
hmpffff__ has quit [Client Quit]
hmpffff has joined #nixos-security
hmpffff_ has joined #nixos-security
hmpffff__ has joined #nixos-security
hmpffff has quit [Ping timeout: 246 seconds]
hmpffff_ has quit [Ping timeout: 268 seconds]
<hexa-> updating fwupd past 1.2.7 has become critical for users of logitech unifying dongles
hmpffff has joined #nixos-security
<hexa-> 19.03 is currently stuck with 1.2.3, which exits with an error when a unifying dongle is connected
<hexa-> master has a pr that would bump it to 1.2.6 which has been stuck for a while https://github.com/NixOS/nixpkgs/pull/56390
<{^_^}> #56390 (by dtzWill, 19 weeks ago, open): fwupd: 1.2.3 -> 1.2.6
<hexa-> this is with regard to https://www.cvedetails.com/cve/CVE-2019-13052/
<hexa-> > Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
<{^_^}> error: syntax error, unexpected IF, expecting ')', at (string):255:49
hmpffff__ has quit [Ping timeout: 258 seconds]
<hexa-> my bad, the pr updates to v1.2.8
<hexa-> which would be fine to get out the firmware fix
hmpffff_ has joined #nixos-security
hmpffff has quit [Ping timeout: 245 seconds]
<hexa-> created an issue as per comment in the pull https://github.com/NixOS/nixpkgs/issues/64631
<{^_^}> #64631 (by mweinelt, 18 seconds ago, open): fwupd upgrade of Logitech Unifying dongles fails on 19.03
<gchristensen> hexa-: hmm we should definitely get that out, not good
<gchristensen> hexa-: you've tested that PR?
<hexa-> sadly not
<hexa-> currently at work, but the build process changed a bit wrt 19.03
<gchristensen> okay
<gchristensen> so
<gchristensen> I'm inclined to merge that PR
<hexa-> worldofpeace stated it's backwards compatibility was los
<hexa-> s/los/low/
<gchristensen> maybe you could help by opening the backport PR?
<hexa-> I can look into that later tonight
<gchristensen> boy, this is a thorny one
<hexa-> nah that looks I'm a bit in over my head, sorry
hmpffff_ has quit [Quit: nchrrrr…]
hmpffff has joined #nixos-security
hmpffff_ has joined #nixos-security
hmpffff has quit [Read error: Connection reset by peer]
hmpffff_ has quit [Quit: nchrrrr…]
justanotheruser has quit [Ping timeout: 248 seconds]