From d7887cf06be1a65974efcf531e65fab155a07757 Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Sat, 2 Dec 2023 21:55:16 +0000 Subject: [PATCH 01/10] mbedtls: add patches for CVE-2023-45199 & CVE-2023-43615 --- .../mbedtls/3.4.0-CVE-2023-45199.patch | 78 +++++++++++++++++++ pkgs/development/libraries/mbedtls/3.nix | 10 ++- .../development/libraries/mbedtls/generic.nix | 3 +- 3 files changed, 89 insertions(+), 2 deletions(-) create mode 100644 pkgs/development/libraries/mbedtls/3.4.0-CVE-2023-45199.patch diff --git a/pkgs/development/libraries/mbedtls/3.4.0-CVE-2023-45199.patch b/pkgs/development/libraries/mbedtls/3.4.0-CVE-2023-45199.patch new file mode 100644 index 000000000000..e114eb25ac36 --- /dev/null +++ b/pkgs/development/libraries/mbedtls/3.4.0-CVE-2023-45199.patch @@ -0,0 +1,78 @@ +Based on upstream 130938a80403647dc22a3e15ca442a500248647b, alterations +mostly due to ecdh_psa_peerkey being renamed xxdh_psa_peerkey upstream + +--- a/library/ssl_tls12_client.c ++++ b/library/ssl_tls12_client.c +@@ -1714,7 +1714,7 @@ static int ssl_parse_server_ecdh_params(mbedtls_ssl_context *ssl, + unsigned char *end) + { + uint16_t tls_id; +- uint8_t ecpoint_len; ++ size_t ecpoint_len; + mbedtls_ssl_handshake_params *handshake = ssl->handshake; + psa_ecc_family_t ec_psa_family = 0; + size_t ec_bits = 0; +@@ -2039,7 +2039,7 @@ static int ssl_get_ecdh_params_from_cert(mbedtls_ssl_context *ssl) + ret = mbedtls_ecp_point_write_binary(&peer_key->grp, &peer_key->Q, + MBEDTLS_ECP_PF_UNCOMPRESSED, &olen, + ssl->handshake->ecdh_psa_peerkey, +- MBEDTLS_PSA_MAX_EC_PUBKEY_LENGTH); ++ sizeof(ssl->handshake->ecdh_psa_peerkey)); + + if (ret != 0) { + MBEDTLS_SSL_DEBUG_RET(1, ("mbedtls_ecp_point_write_binary"), ret); +--- a/library/ssl_tls12_server.c ++++ b/library/ssl_tls12_server.c +@@ -3667,22 +3667,32 @@ static int ssl_parse_client_key_exchange(mbedtls_ssl_context *ssl) + psa_status_t status = PSA_ERROR_GENERIC_ERROR; + mbedtls_ssl_handshake_params *handshake = ssl->handshake; + +- MBEDTLS_SSL_DEBUG_MSG(1, ("Read the peer's public key.")); ++ MBEDTLS_SSL_DEBUG_MSG(3, ("Read the peer's public key.")); + + /* + * We must have at least two bytes (1 for length, at least 1 for data) + */ + if (buf_len < 2) { +- MBEDTLS_SSL_DEBUG_MSG(1, ("Invalid buffer length")); +- return MBEDTLS_ERR_ECP_BAD_INPUT_DATA; ++ MBEDTLS_SSL_DEBUG_MSG(1, ("Invalid buffer length: %" MBEDTLS_PRINTF_SIZET, ++ buf_len)); ++ return MBEDTLS_ERR_SSL_HANDSHAKE_FAILURE; + } + + if (data_len < 1 || data_len > buf_len) { +- MBEDTLS_SSL_DEBUG_MSG(1, ("Invalid data length")); +- return MBEDTLS_ERR_ECP_BAD_INPUT_DATA; ++ MBEDTLS_SSL_DEBUG_MSG(1, ("Invalid data length: %" MBEDTLS_PRINTF_SIZET ++ " > %" MBEDTLS_PRINTF_SIZET, ++ data_len, buf_len)); ++ return MBEDTLS_ERR_SSL_HANDSHAKE_FAILURE; + } + + /* Store peer's ECDH public key. */ ++ if (data_len > sizeof(handshake->ecdh_psa_peerkey)) { ++ MBEDTLS_SSL_DEBUG_MSG(1, ("Invalid public key length: %" MBEDTLS_PRINTF_SIZET ++ " > %" MBEDTLS_PRINTF_SIZET, ++ data_len, ++ sizeof(handshake->ecdh_psa_peerkey))); ++ return MBEDTLS_ERR_SSL_HANDSHAKE_FAILURE; ++ } + memcpy(handshake->ecdh_psa_peerkey, p, data_len); + handshake->ecdh_psa_peerkey_len = data_len; + +--- a/library/ssl_tls13_generic.c ++++ b/library/ssl_tls13_generic.c +@@ -1447,6 +1447,12 @@ int mbedtls_ssl_tls13_read_public_ecdhe_share(mbedtls_ssl_context *ssl, + MBEDTLS_SSL_CHK_BUF_READ_PTR(p, end, peerkey_len); + + /* Store peer's ECDH public key. */ ++ if (peerkey_len > sizeof(handshake->ecdh_psa_peerkey)) { ++ MBEDTLS_SSL_DEBUG_MSG(1, ("Invalid public key length: %u > %" MBEDTLS_PRINTF_SIZET, ++ (unsigned) peerkey_len, ++ sizeof(handshake->ecdh_psa_peerkey))); ++ return MBEDTLS_ERR_SSL_HANDSHAKE_FAILURE; ++ } + memcpy(handshake->ecdh_psa_peerkey, p, peerkey_len); + handshake->ecdh_psa_peerkey_len = peerkey_len; + diff --git a/pkgs/development/libraries/mbedtls/3.nix b/pkgs/development/libraries/mbedtls/3.nix index 67269717bb99..b3a07c8d4309 100644 --- a/pkgs/development/libraries/mbedtls/3.nix +++ b/pkgs/development/libraries/mbedtls/3.nix @@ -1,6 +1,14 @@ -{ callPackage }: +{ callPackage, fetchpatch }: callPackage ./generic.nix { version = "3.4.0"; hash = "sha256-1YA4hp/VEjph5k0qJqhhH4nBbTP3Qu2pl7WpuvPkVfg="; + patches = [ + ./3.4.0-CVE-2023-45199.patch + (fetchpatch { + name = "CVE-2023-43615.patch"; + url = "https://github.com/Mbed-TLS/mbedtls/commit/faf0b8604ac49456b0cff7a34ad27485ca145cce.patch"; + hash = "sha256-GFx+7TmhthRbwBnTgTdNhokftsGwIY7cQGhxKf3WZcE="; + }) + ]; } diff --git a/pkgs/development/libraries/mbedtls/generic.nix b/pkgs/development/libraries/mbedtls/generic.nix index adc46adb75fb..3186f1982b40 100644 --- a/pkgs/development/libraries/mbedtls/generic.nix +++ b/pkgs/development/libraries/mbedtls/generic.nix @@ -3,6 +3,7 @@ , version , hash , fetchFromGitHub +, patches ? [] , cmake , ninja @@ -14,7 +15,7 @@ stdenv.mkDerivation rec { pname = "mbedtls"; - inherit version; + inherit version patches; src = fetchFromGitHub { owner = "Mbed-TLS"; From bd54d15c65a7f702949f5e6084b7856963afc868 Mon Sep 17 00:00:00 2001 From: Raphael Robatsch Date: Thu, 3 Aug 2023 20:26:36 +0200 Subject: [PATCH 02/10] mbedtls_2: 2.28.3 -> 2.28.4 Changelog: https://github.com/Mbed-TLS/mbedtls/blob/v2.28.4/ChangeLog (cherry picked from commit 38642f3dce0fd419d6a822b367aba4d2af997698) --- pkgs/development/libraries/mbedtls/2.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/mbedtls/2.nix b/pkgs/development/libraries/mbedtls/2.nix index 2dd5ae6dae58..3711e2d2b4ff 100644 --- a/pkgs/development/libraries/mbedtls/2.nix +++ b/pkgs/development/libraries/mbedtls/2.nix @@ -1,6 +1,6 @@ { callPackage }: callPackage ./generic.nix { - version = "2.28.3"; - hash = "sha256-w5bJErCNRZLE8rHcuZlK3bOqel97gPPMKH2cPGUR6Zw="; + version = "2.28.4"; + hash = "sha256-88Lnj9NgS5PWg2hydvb9cwi6s6BG3UMvkUH2Ny1jmtE="; } From 47d8f2c2283030d64e818e5c51cb92b96c27b378 Mon Sep 17 00:00:00 2001 From: Weijia Wang <9713184+wegank@users.noreply.github.com> Date: Tue, 7 Nov 2023 02:21:27 +0100 Subject: [PATCH 03/10] mbedtls_2: 2.28.4 -> 2.28.5 (cherry picked from commit 76aa21eab75b91deefd87aa039ee615f18347788) --- pkgs/development/libraries/mbedtls/2.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/mbedtls/2.nix b/pkgs/development/libraries/mbedtls/2.nix index 3711e2d2b4ff..18793114c219 100644 --- a/pkgs/development/libraries/mbedtls/2.nix +++ b/pkgs/development/libraries/mbedtls/2.nix @@ -1,6 +1,6 @@ { callPackage }: callPackage ./generic.nix { - version = "2.28.4"; - hash = "sha256-88Lnj9NgS5PWg2hydvb9cwi6s6BG3UMvkUH2Ny1jmtE="; + version = "2.28.5"; + hash = "sha256-Gl4UQMSvAwYbOi2b/AUMz+zgkOl1o0UA2VveF/3ek8o="; } From 50f790788bbb2c2bfad150da5fd58139975e0346 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 7 Dec 2023 22:15:41 +0000 Subject: [PATCH 04/10] thunderbird-unwrapped: 115.4.2 -> 115.5.1 (cherry picked from commit ded3c035294f7d1304242072f77c22e24638bb1a) --- .../networking/mailreaders/thunderbird/packages.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index ca2e8734c72e..bc264ef07d04 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -43,13 +43,13 @@ rec { thunderbird-115 = (buildMozillaMach rec { pname = "thunderbird"; - version = "115.4.2"; + version = "115.5.1"; application = "comm/mail"; applicationName = "Mozilla Thunderbird"; binaryName = pname; src = fetchurl { url = "mirror://mozilla/thunderbird/releases/${version}/source/thunderbird-${version}.source.tar.xz"; - sha512 = "44cedd5931edbac2ab0babfaf0e71a0262317c01fd7d71e8740bb8f54766c9b49b9e325f1d2796c3a233d4298457d8769b675213a21bef759c46086080bcc8bc"; + sha512 = "5ddc39b3591427d283c5497f68a1d722409aba54d53342a36a259daa219d8135ecf88868b12235eb9536f46f825722cf6da2781b71a2e10b816281231394b4f9"; }; extraPatches = [ # The file to be patched is different from firefox's `no-buildconfig-ffx90.patch`. From bfe6b074c9c1f5f6d301ea8735a4c67f016dde6f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phan=20Kochen?= Date: Tue, 5 Dec 2023 21:56:08 +0100 Subject: [PATCH 05/10] couchdb3: 3.3.2 -> 3.3.3 (cherry picked from commit 2a4c0e2f12cfbf70ecd3bc95d64b939d9e22437d) --- pkgs/servers/http/couchdb/3.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/couchdb/3.nix b/pkgs/servers/http/couchdb/3.nix index 3ce5272c1d93..b6d1ce59b8ba 100644 --- a/pkgs/servers/http/couchdb/3.nix +++ b/pkgs/servers/http/couchdb/3.nix @@ -11,11 +11,11 @@ stdenv.mkDerivation rec { pname = "couchdb"; - version = "3.3.2"; + version = "3.3.3"; src = fetchurl { url = "mirror://apache/couchdb/source/${version}/apache-${pname}-${version}.tar.gz"; - hash = "sha256-PWgj1C0Qzw1PhsnE/lnJkyyJ1oV4/LbEtCeNx2kwjao="; + hash = "sha256-eiAHtfZz1L4iolyaER2QZpGdhy3bkTWn3OwBIimb054="; }; postPatch = '' From 08206e188bd72c03ddba6d9b693b03f462a68b5d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Mon, 11 Dec 2023 07:24:26 +0100 Subject: [PATCH 06/10] Revert "python311Packages.hepmc3: fix build" This reverts commit d63d6cb660f13c1551adce0d0cec6cb15309b3db. It was included in update from 6c4543551fcb6f5ef4b9664a93ffb. --- pkgs/applications/science/misc/root/default.nix | 6 ------ 1 file changed, 6 deletions(-) diff --git a/pkgs/applications/science/misc/root/default.nix b/pkgs/applications/science/misc/root/default.nix index 5426e169b092..cfe18b1450df 100644 --- a/pkgs/applications/science/misc/root/default.nix +++ b/pkgs/applications/science/misc/root/default.nix @@ -122,12 +122,6 @@ stdenv.mkDerivation rec { patches = [ ./sw_vers.patch - ] ++ lib.optionals (python.pkgs.pythonAtLeast "3.11") [ - # Fix build against Python 3.11 - (fetchpatch { - url = "https://github.com/root-project/root/commit/484deb056dacf768aba4954073b41105c431bffc.patch"; - hash = "sha256-4qur2e3SxMIPgOg4IjlvuULR2BObuP7xdvs+LmNT2/s="; - }) ]; # Fix build against vanilla LLVM 9 From 1de49313f4c22dfc918e55566ade374752d5ac64 Mon Sep 17 00:00:00 2001 From: Christian Theune Date: Mon, 11 Dec 2023 08:45:19 +0100 Subject: [PATCH 07/10] yt-dlp: 2023.10.13 -> 2023.11.14 Changelog: https://github.com/yt-dlp/yt-dlp/releases/tag/2023.11.14 (cherry picked from commit 70c19a54d74f22d5da7eeb9599f14f9529277b83) yt-dlp: fix new dependency on requests --- pkgs/tools/misc/yt-dlp/default.nix | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/misc/yt-dlp/default.nix b/pkgs/tools/misc/yt-dlp/default.nix index 8fe478716ede..5f1005506a6e 100644 --- a/pkgs/tools/misc/yt-dlp/default.nix +++ b/pkgs/tools/misc/yt-dlp/default.nix @@ -9,6 +9,7 @@ , pycryptodomex , websockets , mutagen +, requests , secretstorage , atomicparsleySupport ? true , ffmpegSupport ? true @@ -22,11 +23,11 @@ buildPythonPackage rec { # The websites yt-dlp deals with are a very moving target. That means that # downloads break constantly. Because of that, updates should always be backported # to the latest stable release. - version = "2023.10.13"; + version = "2023.11.14"; src = fetchPypi { inherit pname version; - hash = "sha256-4CbqHENf827vEhW8TFu4xHmTi5AFSZe6mfY6RUH+Y7Q="; + hash = "sha256-s8JTU7oQaSLYcKWlnk1qLrhXg+vRfinsQ1vD4XZN6L4="; }; propagatedBuildInputs = [ @@ -34,6 +35,7 @@ buildPythonPackage rec { certifi mutagen pycryptodomex + requests secretstorage # "optional", as in not in requirements.txt, needed for `--cookies-from-browser` websockets ]; @@ -62,6 +64,11 @@ buildPythonPackage rec { ln -s "$out/bin/yt-dlp" "$out/bin/youtube-dl" ''; + postPatch = '' + substituteInPlace requirements.txt \ + --replace "requests>=2.31.0" "requests>=2.29.0" + ''; + passthru.updateScript = [ update-python-libraries (toString ./.) ]; meta = with lib; { From f3ad74fb4d8ef920d161387a27d25e44b7683647 Mon Sep 17 00:00:00 2001 From: K900 Date: Mon, 11 Dec 2023 14:37:41 +0300 Subject: [PATCH 08/10] linux_testing: 6.7-rc4 -> 6.7-rc5 (cherry picked from commit 1053f306894a4c0e591bc65a082f31647f885b1e) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 8c30f8b6c423..66626fb63e28 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -1,7 +1,7 @@ { "testing": { - "version": "6.7-rc4", - "hash": "sha256:1igynlm5pv62brfkyjh6w8lzvmmy8c3g8phrn5wgdyy8svc48r8h" + "version": "6.7-rc5", + "hash": "sha256:125zdj2sxcwkfvm2ckjk3mbwfll8950bn7kr38s5pvlx2a10zv04" }, "6.5": { "version": "6.5.13", From 47f6214770a1b300ebb6f1450b038e9da5e3b6fe Mon Sep 17 00:00:00 2001 From: K900 Date: Mon, 11 Dec 2023 14:37:45 +0300 Subject: [PATCH 09/10] linux_6_6: 6.6.5 -> 6.6.6 (cherry picked from commit b52a1136c3ec28131eeb2fa1673c81e8d6cd5410) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 66626fb63e28..f3c8d50e85f7 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -36,7 +36,7 @@ "hash": "sha256:1f4q0acbp917myjmgiy4haxp78yak5h1rj5g937r6mkykwb6nb14" }, "6.6": { - "version": "6.6.5", - "hash": "sha256:17miac3h4kvj4yyf042qsmpsivpq243db5v0ay6233d6aic7k4kw" + "version": "6.6.6", + "hash": "sha256:1j14n8b012pv3r7i9p762jyabzn2nv1ranxyw5lk3c9lg68hmxzb" } } From d57be119623a8c875b0d5e8e65b6f4c9dd7b31fc Mon Sep 17 00:00:00 2001 From: K900 Date: Mon, 11 Dec 2023 14:37:48 +0300 Subject: [PATCH 10/10] linux_6_1: 6.1.66 -> 6.1.67 (cherry picked from commit 082f3bcfb725d6ed1c5a5740348f5258991bdc30) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index f3c8d50e85f7..c7c73f79db6f 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -12,8 +12,8 @@ "hash": "sha256:0zgj1z97jyx7wf12zrnlcp0mj4cl43ais9qsy6dh1jwylf2fq9ln" }, "6.1": { - "version": "6.1.66", - "hash": "sha256:030sxwzqlf9jg57j1hvd46ffkc9yfplbk3b81faycfa2dk6n57j1" + "version": "6.1.67", + "hash": "sha256:11cjqll3b7iq3mblwyzjrd5ph8avgk23f4mw4shm8j6ai5rdndvm" }, "5.15": { "version": "5.15.142",