andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: + | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
<{^_^}> #116568 (by mweinelt, 2 days ago, open): [20.09] python3Packages.aiohttp: 3.6.2 -> 3.6.3; patch CVE-2021-21330
<{^_^}> #115310 (by mweinelt, 1 week ago, open): grub: 2.0.4 -> 2.0.6-rc1
<{^_^}> #116280 (by mweinelt, 5 days ago, open): [20.09] libtiff: fix two security issues
<{^_^}> #116431 (by dasJ, 4 days ago, open): [staging-20.09] openssh: 8.4p1 -> 8.5p1 and mark CVE-2021-28041
<hexa-> this looks like quite the extensive backport
<supersandro2000> IIRC the packages that depend on openssh did not receive an update at the time and they needed to be split out
<supersandro2000> I tried a smaller PR but it ended up being more or less the same
