From 2f11bafa9a8b60be718b5a8b5ed92caa8c5f9243 Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Sat, 8 Jul 2023 11:06:06 +0200 Subject: [PATCH 01/10] mattermost: 7.8.5 -> 7.8.8 Fixes security issues MMSA-2023-00190, MMSA-2023-00175, MMSA-2023-00202, MMSA-2023-00174, MMSA-2023-00169, MMSA-2023-00186, MMSA-2023-00200, MMSA-2023-00178, MMSA-2023-00185, MMSA-2023-00176, MMSA-2023-00147 and MMSA-2023-00168. Changelog: https://docs.mattermost.com/install/self-managed-changelog.html#release-v7-8-extended-support-release --- pkgs/servers/mattermost/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/mattermost/default.nix b/pkgs/servers/mattermost/default.nix index 97d8f06850ce..864856fad13f 100644 --- a/pkgs/servers/mattermost/default.nix +++ b/pkgs/servers/mattermost/default.nix @@ -7,18 +7,18 @@ buildGoModule rec { pname = "mattermost"; - version = "7.8.5"; + version = "7.8.8"; src = fetchFromGitHub { owner = "mattermost"; repo = "mattermost-server"; rev = "v${version}"; - hash = "sha256-qC6tJcWruiTbWXKuACuhl0kwbRdPVXfUlaFJx4DiQgE="; + hash = "sha256-U12vAEyL7epfySonW1eYe2YHK2DLrKVX73ouAHysNls="; }; webapp = fetchurl { url = "https://releases.mattermost.com/${version}/mattermost-${version}-linux-amd64.tar.gz"; - hash = "sha256-ojAGa4tZ5aZp+4XSW6ycDvJ295zH8GaYsA9w6z8n2WM="; + hash = "sha256-Vzz2eIcvjts0e/+EUQzls5yPglcCtzaZr0XUf2By1sM="; }; vendorHash = "sha256-VvGLYOESyoBpFmIibHWxazliHcscMxf3KcQ46NQ4syk="; From c3c1c300657a468d6e3058ca549e6d114cf7dd43 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Wed, 12 Jul 2023 21:04:34 -0700 Subject: [PATCH 02/10] irrd: mark insecure --- pkgs/servers/irrd/default.nix | 60 +++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) diff --git a/pkgs/servers/irrd/default.nix b/pkgs/servers/irrd/default.nix index 13dc0bb0b196..cddb68eca7bb 100644 --- a/pkgs/servers/irrd/default.nix +++ b/pkgs/servers/irrd/default.nix @@ -33,6 +33,66 @@ let ]; }); + hiredis = super.hiredis.overridePythonAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ + "CVE-2021-32765" + ]; + }; + }); + + pydantic = super.pydantic.overridePythonAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ + "CVE-2020-10735" + ]; + }; + }); + + redis = super.redis.overridePythonAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ + "CVE-2023-28858" + "CVE-2023-28859" + ]; + }; + }); + + requests = super.requests.overridePythonAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ + "CVE-2023-32681" + ]; + }; + }); + + sqlalchemy = super.sqlalchemy.overridePythonAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ + "PVE-2022-51668" + ]; + }; + }); + + starlette = super.starlette.overridePythonAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ + "CVE-2023-29159" + "CVE-2023-30798" + ]; + }; + }); + + ujson = super.ujson.overridePythonAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ + "CVE-2021-45958" + "CVE-2022-31116" + "CVE-2022-31117" + ]; + }; + }); + }) ]; }).python.pkgs; From c894859b03f164a5c0b1455646b61bbaa65bb2e2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Sat, 1 Jul 2023 08:19:44 +0200 Subject: [PATCH 03/10] nixos: show which files are related to "not applying GID/UID change" I initially thought it was related to /var/lib/nixos/{gid-map,uid-map}, but it seems that to migrate GID/UID you have to edit /etc/{group,passwd} (and update GID/UID in all files). So mention those files in the warning messages. (cherry picked from commit 15bd330b068cab4ec207db11dd7fc53ebe27732a) --- nixos/modules/config/update-users-groups.pl | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/modules/config/update-users-groups.pl b/nixos/modules/config/update-users-groups.pl index 54352a517a24..75c343523e27 100644 --- a/nixos/modules/config/update-users-groups.pl +++ b/nixos/modules/config/update-users-groups.pl @@ -147,7 +147,7 @@ foreach my $g (@{$spec->{groups}}) { if (defined $existing) { $g->{gid} = $existing->{gid} if !defined $g->{gid}; if ($g->{gid} != $existing->{gid}) { - dry_print("warning: not applying", "warning: would not apply", "GID change of group ‘$name’ ($existing->{gid} -> $g->{gid})"); + dry_print("warning: not applying", "warning: would not apply", "GID change of group ‘$name’ ($existing->{gid} -> $g->{gid}) in /etc/group"); $g->{gid} = $existing->{gid}; } $g->{password} = $existing->{password}; # do we want this? @@ -209,7 +209,7 @@ foreach my $u (@{$spec->{users}}) { if (defined $existing) { $u->{uid} = $existing->{uid} if !defined $u->{uid}; if ($u->{uid} != $existing->{uid}) { - dry_print("warning: not applying", "warning: would not apply", "UID change of user ‘$name’ ($existing->{uid} -> $u->{uid})"); + dry_print("warning: not applying", "warning: would not apply", "UID change of user ‘$name’ ($existing->{uid} -> $u->{uid}) in /etc/passwd"); $u->{uid} = $existing->{uid}; } } else { From 85de27f037d43de4b4ad0711abd508ce948da505 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Fri, 14 Jul 2023 21:27:43 +0200 Subject: [PATCH 04/10] betterbird: inherit from correct thunderbird (cherry picked from commit 2a9010bfb42d4f9d4ad082fde409e39255f174a9) --- .../networking/mailreaders/betterbird/default.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/applications/networking/mailreaders/betterbird/default.nix b/pkgs/applications/networking/mailreaders/betterbird/default.nix index 1b08cc3eb082..d08bd5dfcc4a 100644 --- a/pkgs/applications/networking/mailreaders/betterbird/default.nix +++ b/pkgs/applications/networking/mailreaders/betterbird/default.nix @@ -6,10 +6,12 @@ , git , libdbusmenu-gtk3 , runtimeShell -, thunderbird-unwrapped +, thunderbirdPackages }: let + thunderbird-unwrapped = thunderbirdPackages.thunderbird-102; + version = "102.12.0"; majVer = lib.versions.major version; From 7b2995fc2c406346b2fe9ba668d6b4d88b67b538 Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Fri, 14 Jul 2023 12:17:43 +0200 Subject: [PATCH 05/10] asterisk: apply patch for pjsip CVE-2023-27585 https://github.com/pjsip/pjproject/security/advisories/GHSA-q9cp-8wcq-7pfr (cherry picked from commit 2a3d3107090ef1e54773925ff6f109c820b2a6f0) --- pkgs/servers/asterisk/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/servers/asterisk/default.nix b/pkgs/servers/asterisk/default.nix index c49e5696a676..6d0b4c5805ea 100644 --- a/pkgs/servers/asterisk/default.nix +++ b/pkgs/servers/asterisk/default.nix @@ -48,6 +48,11 @@ let url = "https://github.com/pjsip/pjproject/commit/bc4812d31a67d5e2f973fbfaf950d6118226cf36.patch"; sha256 = "sha256-bpc8e8VAQpfyl5PX96G++6fzkFpw3Or1PJKNPKl7N5k="; }) + (fetchpatch { + name = "CVE-2023-27585.patch"; + url = "https://github.com/pjsip/pjproject/commit/d1c5e4da5bae7f220bc30719888bb389c905c0c5.patch"; + hash = "sha256-+yyKKTKG2FnfyLWnc4S80vYtDzmiu9yRmuqb5eIulPg="; + }) ]; common = { version, sha256, externals, pjsip_patches ? [ ] }: stdenv.mkDerivation { From 9bbe18fc7030fa7784bc95c80dde00dfa5271669 Mon Sep 17 00:00:00 2001 From: Nicolas Benes Date: Tue, 11 Jul 2023 22:36:06 +0200 Subject: [PATCH 06/10] kernelshark: 2.2.0 -> 2.2.1 (cherry picked from commit de2ac3cf0e2a38edc1e41d29bfe083c14c409f29) --- pkgs/os-specific/linux/trace-cmd/kernelshark.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/trace-cmd/kernelshark.nix b/pkgs/os-specific/linux/trace-cmd/kernelshark.nix index e492bc2403fd..23ebbae8d1cb 100644 --- a/pkgs/os-specific/linux/trace-cmd/kernelshark.nix +++ b/pkgs/os-specific/linux/trace-cmd/kernelshark.nix @@ -5,12 +5,12 @@ mkDerivation rec { pname = "kernelshark"; - version = "2.2.0"; + version = "2.2.1"; src = fetchgit { url = "https://git.kernel.org/pub/scm/utils/trace-cmd/kernel-shark.git/"; rev = "kernelshark-v${version}"; - sha256 = "sha256-VkUah8qAlOck9245f/zngtVpHmJdx6eQXqwzLwK2xjU="; + hash = "sha256-V25IzPDOt6V03wgIa/AJ0T8mRaGmXYuMCcvbSOKleY0="; }; outputs = [ "out" ]; From 4fce6becb702ee2017db89b6aeb8bb565a767c15 Mon Sep 17 00:00:00 2001 From: Ashish SHUKLA Date: Wed, 24 May 2023 10:18:14 +0200 Subject: [PATCH 07/10] openssh_hpn: 9.2p1 -> 9.3p1 (cherry picked from commit 03c969f0cbf769c99bb2d5ef74ed567d9dd0e745) --- pkgs/tools/networking/openssh/default.nix | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/pkgs/tools/networking/openssh/default.nix b/pkgs/tools/networking/openssh/default.nix index 9b604cd1405c..e05d0ce144b2 100644 --- a/pkgs/tools/networking/openssh/default.nix +++ b/pkgs/tools/networking/openssh/default.nix @@ -19,32 +19,33 @@ in openssh_hpn = common rec { pname = "openssh-with-hpn"; - version = "9.2p1"; + version = "9.3p1"; extraDesc = " with high performance networking patches"; src = fetchurl { url = "mirror://openbsd/OpenSSH/portable/openssh-${version}.tar.gz"; - hash = "sha256-P2bb8WVftF9Q4cVtpiqwEhjCKIB7ITONY068351xz0Y="; + hash = "sha256-6bq6dwGnalHz2Fpiw4OjydzZf6kAuFm8fbEUwYaK+Kg="; }; - extraPatches = [ + extraPatches = let url = "https://raw.githubusercontent.com/freebsd/freebsd-ports/700625bcd86b74cf3fb9536aeea250d7f8cd1fd5/security/openssh-portable/files/extra-patch-hpn"; in + [ ./ssh-keysign-8.5.patch # HPN Patch from FreeBSD ports (fetchpatch { name = "ssh-hpn-wo-channels.patch"; - url = "https://raw.githubusercontent.com/freebsd/freebsd-ports/10491773d88012fe81d9c039cbbba647bde9ebc9/security/openssh-portable/files/extra-patch-hpn"; + inherit url; stripLen = 1; excludes = [ "channels.c" ]; - sha256 = "sha256-kSj0oE7gNHfIciy0/ErhdfrbmfjQmd8hduyiRXFnVZA="; + hash = "sha256-hYB3i0ifNOgGLYwElMJFcT+ktczLKciq3qw1tTHZHcc="; }) (fetchpatch { name = "ssh-hpn-channels.patch"; - url = "https://raw.githubusercontent.com/freebsd/freebsd-ports/10491773d88012fe81d9c039cbbba647bde9ebc9/security/openssh-portable/files/extra-patch-hpn"; + inherit url; extraPrefix = ""; includes = [ "channels.c" ]; - sha256 = "sha256-pDLUbjv5XIyByEbiRAXC3WMUPKmn15af1stVmcvr7fE="; + hash = "sha256-pDLUbjv5XIyByEbiRAXC3WMUPKmn15af1stVmcvr7fE="; }) ]; @@ -53,7 +54,6 @@ in extraConfigureFlags = [ "--with-hpn" ]; extraMeta = { maintainers = with lib.maintainers; [ abbe ]; - knownVulnerabilities = [ "CVE-2023-28531" ]; }; }; From 05ad53d5c506cb199dc24ab418ca44b517f67a78 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Thu, 20 Jul 2023 09:33:56 +0200 Subject: [PATCH 08/10] iperf: 3.13 -> 3.14 (#244430) Fixes CVE-2023-38403. https://github.com/esnet/iperf/blob/3.14/RELNOTES.md (cherry picked from commit aba7faf480cc1f667b16333bfae14df9fb0ab649) Co-authored-by: Thomas Gerbet --- pkgs/tools/networking/iperf/3.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/tools/networking/iperf/3.nix b/pkgs/tools/networking/iperf/3.nix index f201d863b7a3..41323b55d2f5 100644 --- a/pkgs/tools/networking/iperf/3.nix +++ b/pkgs/tools/networking/iperf/3.nix @@ -2,11 +2,11 @@ stdenv.mkDerivation rec { pname = "iperf"; - version = "3.13"; + version = "3.14"; src = fetchurl { url = "https://downloads.es.net/pub/iperf/iperf-${version}.tar.gz"; - sha256 = "sha256-vuQnrrE9ai7iIHPyMmH2NxLYK++qg6yMtNtdpMK9yGU="; + hash = "sha256-cj/MQwoCe8aVJij6KjrHdYSh0L0ygnXlc/ybIGwVUAQ="; }; buildInputs = [ openssl ] ++ lib.optionals stdenv.isLinux [ lksctp-tools ]; @@ -30,7 +30,7 @@ stdenv.mkDerivation rec { ''; meta = with lib; { - homepage = "http://software.es.net/iperf/"; + homepage = "https://software.es.net/iperf/"; description = "Tool to measure IP bandwidth using UDP or TCP"; platforms = platforms.unix; license = licenses.bsd3; From ac4bb597bb142f559bf3f901abf0f50f3bb782ef Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 5 Jul 2023 09:31:59 +0200 Subject: [PATCH 09/10] gdc: switch to gdc11 for now That way it will at least evaluate and build. Fixes #241341 (cherry picked from commit 15f3926baa32c4eb7b73d6b25c9d4de40358d0f6) --- pkgs/top-level/all-packages.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 70f9273827fe..2a4c4a8647dc 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -15388,9 +15388,10 @@ with pkgs; gcc-arm-embedded-12 = callPackage ../development/compilers/gcc-arm-embedded/12 { }; gcc-arm-embedded = gcc-arm-embedded-12; - # Has to match the default gcc so that there are no linking errors when - # using C/C++ libraries in D packages - gdc = wrapCC (gcc.cc.override { + # It would be better to match the default gcc so that there are no linking errors + # when using C/C++ libraries in D packages, but right now versions >= 12 are broken. + gdc = gdc11; + gdc11 = wrapCC (gcc11.cc.override { name = "gdc"; langCC = false; langC = false; From fa793b06f56896b7d1909e4b69977c7bf842b2f0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Thu, 20 Jul 2023 22:44:40 +0200 Subject: [PATCH 10/10] Revert Merge #242473: edk2: 202211 -> 202305 This reverts commit 242a519286787cfcf83b99222cb883360a4b671f, reversing changes made to 1e135b35ae02941114684a2705c72f967369f534. See that PR for discussion. Channels would keep blocked without this. --- pkgs/development/compilers/edk2/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/edk2/default.nix b/pkgs/development/compilers/edk2/default.nix index 34b75b05d87f..878d3f756838 100644 --- a/pkgs/development/compilers/edk2/default.nix +++ b/pkgs/development/compilers/edk2/default.nix @@ -36,7 +36,7 @@ buildType = if stdenv.isDarwin then edk2 = buildStdenv.mkDerivation { pname = "edk2"; - version = "202305"; + version = "202211"; patches = [ # pass targetPrefix as an env var @@ -52,7 +52,7 @@ edk2 = buildStdenv.mkDerivation { repo = "edk2"; rev = "edk2-stable${edk2.version}"; fetchSubmodules = true; - hash = "sha256-htOvV43Hw5K05g0SF3po69HncLyma3BtgpqYSdzRG4s="; + sha256 = "sha256-0jE73xPyenAcgJ1mS35oTc5cYw7jJvVYxhPdhTWpKA0="; }; nativeBuildInputs = [ pythonEnv ];