andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: + | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
<red[evilred]> I guess we gotta pushh and backport that on Monday then
<blitzclone[m]> hello everyone. I've seen crash on some of our binaries that we produce at work and I thought it's a good thing to hunt these crashes down. I assume that bugs (incl memory unsafety) in patchelf is not a security issue and I can just open issues with example files on github. If someone thinks this is a poor idea, please ping me :)
<andi-> blitzclone[m]: just open it up. I am sure eelco will respond accordingly :-)
<MichaelRaskin> Most uses of patchelf imply execution of the resulting binary in isolation no stricter than patchelf had, so should not be too highly sensitive
<MichaelRaskin> (which does not make it any less serious if it can be triggered inadvertently, of course — just reduces disclosure considerations)
<blitzclone[m]> MichaelRaskin: yes, that's what I thought as well
