andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
rajivr has joined #nixos-security
zgrep has quit [Quit: It's a quitter's world.]
zgrep has joined #nixos-security
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
justanotheruser has joined #nixos-security
kalbasit_ has joined #nixos-security
anselmolsm has quit [Quit: Konversation terminated!]
hexa- has quit [*.net *.split]
cemguresci[m] has quit [*.net *.split]
thefloweringash has quit [*.net *.split]
Raito_Bezarius has quit [*.net *.split]
jdnixx-M has quit [*.net *.split]
joepie91 has quit [*.net *.split]
hexa- has joined #nixos-security
jdnixx-M has joined #nixos-security
joepie91 has joined #nixos-security
colemickens has quit [Ping timeout: 246 seconds]
danielrf[m] has quit [Ping timeout: 240 seconds]
Yakulu[m] has quit [Ping timeout: 240 seconds]
aanderse has quit [Ping timeout: 248 seconds]
Ox4A6F has quit [Ping timeout: 248 seconds]
immae has quit [Ping timeout: 248 seconds]
julianst[m] has quit [Ping timeout: 260 seconds]
nh2[m] has quit [Ping timeout: 260 seconds]
bbigras has quit [Ping timeout: 260 seconds]
JJJollyjim has quit [Ping timeout: 260 seconds]
Raito_Bezarius has joined #nixos-security
Raito_Bezarius has quit [*.net *.split]
Raito_Bezarius has joined #nixos-security
immae has joined #nixos-security
bbigras has joined #nixos-security
colemickens has joined #nixos-security
thefloweringash has joined #nixos-security
julianst[m] has joined #nixos-security
Raito_Bezarius has quit [*.net *.split]
Raito_Bezarius has joined #nixos-security
Raito_Bezarius has quit [Max SendQ exceeded]
colemickens has quit [Ping timeout: 260 seconds]
thefloweringash has quit [Ping timeout: 240 seconds]
bbigras has quit [Ping timeout: 246 seconds]
immae has quit [Ping timeout: 265 seconds]
julianst[m] has quit [Ping timeout: 258 seconds]
Yakulu[m] has joined #nixos-security
danielrf[m] has joined #nixos-security
aanderse has joined #nixos-security
Ox4A6F has joined #nixos-security
nh2[m] has joined #nixos-security
cemguresci[m] has joined #nixos-security
bbigras has joined #nixos-security
immae has joined #nixos-security
thefloweringash has joined #nixos-security
colemickens has joined #nixos-security
julianst[m] has joined #nixos-security
kalbasit_ has quit [Ping timeout: 265 seconds]
faffolter has joined #nixos-security
davidtwco_ has quit [Ping timeout: 260 seconds]
davidtwco_ has joined #nixos-security
WilliButz has quit [Ping timeout: 264 seconds]
ckauhaus has joined #nixos-security
WilliButz has joined #nixos-security
kalbasit has quit [Ping timeout: 272 seconds]
cole-h has quit [Quit: Goodbye]
kalbasit has joined #nixos-security
WilliButz has quit [Ping timeout: 240 seconds]
WilliButz has joined #nixos-security
<aminechikhaoui> Hi anyone knows if there is a distro that prepared CVE-2021-3156 patches for older sudo releases like 1.8.31 ?
<aminechikhaoui> I'm thinking of applying such patches to 20.03 if it's not already doomed with major security problems :)
<Foxboron> RedHat, Ubuntu and SUSE are likely candidates to do that work
<Foxboron> They should also list fixed versions in the advisory, so you can probably figure out which ones have backported the patches
<Foxboron> You could also ask on oss-security
qyliss has quit [Quit: bye]
qyliss has joined #nixos-security
<aminechikhaoui> Foxboron thanks, I think I found the Ubuntu patches
<Foxboron> Lovely :) nps
<qyliss> I think if we want to fix 20.03 we'd be better just putting it on latest sudo
<aminechikhaoui> qyliss yeah that might be even easier, I can prepare a PR with that
<aminechikhaoui> I guess it's unlikely that packages that would depend on sudo would break due to the update
<qyliss> we'll want to double check with the RMs maybe
<aminechikhaoui> yeah, I'm testing the ubuntu patches, they seem to apply cleanly. We can do either way based on RMs preference.
<qyliss> I've been trying to figure out who the RMs are
<qyliss> can never remember how to check
<aminechikhaoui> hm good point, https://discourse.nixos.org/t/21-05-call-for-release-manager/10204/14 seems only Jon is the one for sure for next release unless it was announced elsewhere
<qyliss> well we want the 20.03 RMs
<aminechikhaoui> ohh
<aminechikhaoui> worlofpeace tagged 20.03 at least, yeah we should have a page with the previous RMs
<aminechikhaoui> created https://github.com/NixOS/nixpkgs/pull/110943 with a simple update for now
<{^_^}> #110943 (by AmineChikhaoui, 37 seconds ago, open): sudo: 1.8.31 -> 1.9.5p2
rajivr has quit [Ping timeout: 260 seconds]
davidtwco_ has quit [Ping timeout: 260 seconds]
midchildan has quit [Read error: Connection reset by peer]
elvishjerricco has quit [Read error: Connection reset by peer]
feepo has quit [Write error: Connection reset by peer]
nh2 has quit [Write error: Connection reset by peer]
raboof has quit [Write error: Connection reset by peer]
prusnak has quit [Write error: Connection reset by peer]
elvishjerricco has joined #nixos-security
nh2 has joined #nixos-security
raboof has joined #nixos-security
midchildan has joined #nixos-security
prusnak has joined #nixos-security
feepo has joined #nixos-security
davidtwco_ has joined #nixos-security
rajivr has joined #nixos-security
rajivr has quit [Read error: Connection reset by peer]
rajivr has joined #nixos-security
rajivr has quit [Quit: Connection closed for inactivity]
midchildan has quit [Read error: Connection reset by peer]
raboof has quit [Ping timeout: 256 seconds]
midchildan has joined #nixos-security
raboof has joined #nixos-security
midchildan has quit [Read error: Connection reset by peer]
raboof has quit [Read error: Connection reset by peer]
prusnak has quit [Read error: Connection reset by peer]
raboof has joined #nixos-security
prusnak has joined #nixos-security
midchildan has joined #nixos-security
prusnak has quit [Read error: Connection reset by peer]
midchildan has quit [Read error: Connection reset by peer]
raboof has quit [Ping timeout: 264 seconds]
prusnak has joined #nixos-security
midchildan has joined #nixos-security
raboof has joined #nixos-security
prusnak has quit [Read error: Connection reset by peer]
midchildan has quit [Read error: Connection reset by peer]
raboof has quit [Read error: Connection reset by peer]
glowpelt has quit [Ping timeout: 260 seconds]
colemickens has quit [Ping timeout: 260 seconds]
hax404 has quit [Ping timeout: 260 seconds]
glowpelt has joined #nixos-security
colemickens has joined #nixos-security
hax404 has joined #nixos-security
midchildan has joined #nixos-security
prusnak has joined #nixos-security
raboof has joined #nixos-security
<gchristensen> the vending machine itself is like $3k
cole-h has joined #nixos-security
copumpkin has quit [Quit: Bye!]
prusnak has quit [Read error: Connection reset by peer]
raboof has quit [Read error: Connection reset by peer]
raboof has joined #nixos-security
copumpkin has joined #nixos-security
prusnak has joined #nixos-security
dstzd has quit [Quit: ZNC - https://znc.in]
dstzd has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
ckauhaus has quit [Quit: WeeChat 2.7.1]
nh2[m] has quit [Ping timeout: 246 seconds]
Ox4A6F has quit [Ping timeout: 240 seconds]
Yakulu[m] has quit [Ping timeout: 240 seconds]
colemickens has quit [Ping timeout: 240 seconds]
bbigras has quit [Ping timeout: 258 seconds]
cemguresci[m] has quit [Ping timeout: 258 seconds]
immae has quit [Ping timeout: 268 seconds]
jdnixx-M has quit [Ping timeout: 258 seconds]
thefloweringash has quit [Ping timeout: 265 seconds]
aanderse has quit [Ping timeout: 265 seconds]
danielrf[m] has quit [Ping timeout: 265 seconds]
julianst[m] has quit [Ping timeout: 258 seconds]
dstzd has quit [Quit: ZNC - https://znc.in]
dstzd_ has joined #nixos-security
dstzd_ is now known as dstzd
tokudan has quit [Remote host closed the connection]
tokudan has joined #nixos-security
tokudan has quit [Remote host closed the connection]
tokudan has joined #nixos-security
joepie91 has quit [*.net *.split]
joepie91 has joined #nixos-security
dstzd has quit [Quit: ZNC - https://znc.in]
dstzd has joined #nixos-security
nh2[m] has joined #nixos-security
jdnixx-M has joined #nixos-security
nh2[m] has quit [Quit: Bridge terminating on SIGTERM]
jdnixx-M has quit [Client Quit]
jdnixx-M has joined #nixos-security
bbigras has joined #nixos-security
nh2[m] has joined #nixos-security
thefloweringash has joined #nixos-security
danielrf[m] has joined #nixos-security
aanderse has joined #nixos-security
immae has joined #nixos-security
julianst[m] has joined #nixos-security
Yakulu[m] has joined #nixos-security
colemickens has joined #nixos-security
cemguresci[m] has joined #nixos-security
Ox4A6F has joined #nixos-security
JJJollyjim has joined #nixos-security
faffolter has quit [Ping timeout: 265 seconds]
tilpner has quit [Remote host closed the connection]
tilpner has joined #nixos-security