andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: + | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
<hexa-> Openssl will release new update on 2021/03/25, it will fix two "High" severity issues. These issues does not affect OpenSSL versions before 1.1.1:
<hexa-> CVE-2021-3449: NULL pointer deref in signature_algorithms processing
<hexa-> CVE-2021-3450: CA certificate check bypass with X509_V_FLAG_X509_STRICT
<gchristensen> oh fucking god
<hexa-> thank you Wind River Linux LTS 17
<gchristensen> hm?
<gchristensen> oh
<hexa-> the embargo is valid until tomorrow
<Foxboron> Shouldnt that be under embargo
<gchristensen> welp
<simpson> It is Wednesday my dudes
<gchristensen> yeah I realized the embargo was broken but didn't realize windriver wasn't win driver, but wind river and ... well here we go
<supersandro2000> also thought since when windows is interesting for nixos
<hexa-> fair
<hexa-> the release for 1.1.1k is scheduled for 13:00 - 17:00 UTC tomorrow
<gchristensen> thanks hexa-
<hexa-> guess I'll take care of it if noone beats me to it
<gchristensen> that would be great :)
<aanderse> hexa-++
<{^_^}> hexa-'s karma got increased to 24
<FRidh> staging-20.09 is almost finished, just in time for another round tomorrow with those fixes...
<gchristensen> please don't merge staging until after openssl is released in to channels
<gchristensen> thank you a lot :)
<FRidh> robert and vcunat mostly take care of 20.09
