gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
justanotheruser has quit [Ping timeout: 240 seconds]
justanotheruser has joined #nixos-security
Synthetica has quit [Quit: Connection closed for inactivity]
ris has quit [Ping timeout: 258 seconds]
{^_^} has quit [Remote host closed the connection]
{^_^} has joined #nixos-security
ckauhaus[afk] is now known as ckauhaus
<ckauhaus> reviewing PRs for qemu
<ckauhaus> we have a bump to 4.0.1 in #72236 and a patch for 4.0.0 in #70269
<{^_^}> https://github.com/NixOS/nixpkgs/pull/72236 (by kmcopper4, 22 hours ago, open): [r19.09] [Security] qemu: 4.0.0 -> 4.0.1
<{^_^}> https://github.com/NixOS/nixpkgs/pull/70269 (by delroth, 3 weeks ago, open): qemu: apply patch for CVE-2019-13164 [19.09]
<ckauhaus> I wonder if these should be stacked or if the bump to 4.0.1 already contains a fix for CVE-2019-13164
<ckauhaus> https://wiki.qemu.org/ChangeLog/4.0 is not very clear
pie_ has quit [Ping timeout: 240 seconds]
pie_ has joined #nixos-security
vesper has joined #nixos-security
vesper11 has quit [Ping timeout: 268 seconds]
hmpffff has joined #nixos-security
Synthetica has joined #nixos-security
__Sander__ has joined #nixos-security
FRidh has joined #nixos-security
ckauhaus is now known as ckauhaus[afk]
<globin> ckauhaus: could check if the patch still applies?
tokudan[m] has quit [Write error: Connection reset by peer]
aanderse has quit [Read error: Connection reset by peer]
timokau[m] has quit [Write error: Connection reset by peer]
aanderse has joined #nixos-security
timokau[m] has joined #nixos-security
tokudan[m] has joined #nixos-security
hmpffff has quit [Quit: Bye…]
aminechikhaoui has quit [Quit: The Lounge - https://thelounge.github.io]
aminechikhaoui has joined #nixos-security
ckauhaus[afk] is now known as ckauhaus
<ckauhaus> globin: patching fails on 4.0.1
Synthetica has quit [Quit: Connection closed for inactivity]
<flokli> yes, but how does the code on 4.0.1 look like?
hmpffff has joined #nixos-security
filemon_ has joined #nixos-security
filemon has quit [Ping timeout: 268 seconds]
filemon__ has joined #nixos-security
filemon_ has quit [Ping timeout: 265 seconds]
filemon_ has joined #nixos-security
filemon__ has quit [Ping timeout: 240 seconds]
filemon_ has quit [Ping timeout: 240 seconds]
filemon_ has joined #nixos-security
filemon__ has joined #nixos-security
filemon__ has quit [Read error: Connection reset by peer]
filemon_ has quit [Ping timeout: 265 seconds]
__Sander__ has quit [Quit: Konversation terminated!]
hmpffff has quit [Quit: nchrrrr…]
ris has joined #nixos-security
FRidh has quit [Quit: Konversation terminated!]
hmpffff has joined #nixos-security
ckauhaus has quit [Quit: WeeChat 2.6]
<ivan> https://github.com/NixOS/nixpkgs/issues/67234#issuecomment-547948346 should look for all similar cases because this could be exploitable