Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(build): Revert "sec(libxml2): SECURITY FIX Address CVE-2025-24928… #96

Merged
merged 1 commit into from
Feb 25, 2025

Conversation

daniel-noland
Copy link
Collaborator

… / OSV-2025-74"

This experiment has run its course and we got a fair bit out of it IMO. That said, 3 1/2 hour build times are not my jam so let's revert this.

This reverts commit 5b72937.

…/ OSV-2025-74"

This experiment has run its course and we got a fair bit out of it IMO.
That said, 3 1/2 hour build times are not my jam so let's revert this.

This reverts commit 5b72937.

Signed-off-by: Daniel Noland <[email protected]>
@daniel-noland daniel-noland force-pushed the pr/daniel-noland/revert-sec-fix branch from 02aa1a3 to dc85444 Compare February 24, 2025 23:34
@daniel-noland daniel-noland self-assigned this Feb 24, 2025
@daniel-noland daniel-noland marked this pull request as ready for review February 24, 2025 23:43
Copy link
Contributor

Outdated packages (gnu64):

priority nix_package version_local version_nixpkgs version_upstream
13 glibc 2.40-66 2.40-66 2.41
12 libxml2 2.13.5 2.13.5 2.13.6
12 libffi 3.4.6 3.4.6 3.4.7
11 zstd 1.5.6 1.5.6 1.5.7
11 binutils 2.43.1 2.43.1 2.44
11 mimalloc 2.1.8 2.1.8 3.0.1
10 pcre2 10.44 10.44 10.45
10 isl 0.20 0.24 0.27
5 curl 8.11.1 8.12.0 8.12.1
5 perl 5.40.0 5.40.0 5.40.1
4 sqlite 3.47.2 3.48.0 3.49.1
4 kmod 31 31 34
4 numactl 2.0.18 2.0.18 2.0.19
2 dpdk 24.11.1 24.07 24.11.1

Copy link
Contributor

Vulnerable packages (gnu64):

vuln_id url package severity version_local version_nixpkgs version_upstream package_repology sortcol classify
OSV-2025-74 https://osv.dev/OSV-2025-74 libxml2 2.13.5 2.13.5 2.13.6 libxml2 2025A0000000074 err_not_vulnerable_based_on_repology
CVE-2024-13176 https://nvd.nist.gov/vuln/detail/CVE-2024-13176 openssl 4.1 3.3.2 3.4.1 3.4.1 openssl 2024A0000013176 err_not_vulnerable_based_on_repology
CVE-2024-12797 https://nvd.nist.gov/vuln/detail/CVE-2024-12797 openssl 6.3 3.3.2 3.4.1 3.4.1 openssl 2024A0000012797 err_not_vulnerable_based_on_repology
CVE-2024-9143 https://nvd.nist.gov/vuln/detail/CVE-2024-9143 openssl 4.3 3.3.2 3.4.1 3.4.1 openssl 2024A0000009143 err_not_vulnerable_based_on_repology
OSV-2024-1209 https://osv.dev/OSV-2024-1209 libxml2 2.13.5 2.13.5 2.13.6 libxml2 2024A0000001209 err_not_vulnerable_based_on_repology
OSV-2024-817 https://osv.dev/OSV-2024-817 libpcap 1.10.5 1.10.5 1.10.5 libpcap 2024A0000000817 err_not_vulnerable_based_on_repology
OSV-2024-395 https://osv.dev/OSV-2024-395 libpcap 1.10.5 1.10.5 1.10.5 libpcap 2024A0000000395 err_not_vulnerable_based_on_repology
CVE-2023-6992 https://nvd.nist.gov/vuln/detail/CVE-2023-6992 zlib 5.5 1.3.1 1.3.1 1.3.1 zlib 2023A0000006992 err_not_vulnerable_based_on_repology
CVE-2023-4039 https://nvd.nist.gov/vuln/detail/CVE-2023-4039 gcc 4.8 14-20241116 2023A0000004039 err_missing_repology_version
OSV-2023-1307 https://osv.dev/OSV-2023-1307 libbpf 1.5.0 1.5.0 1.5.0 libbpf 2023A0000001307 err_not_vulnerable_based_on_repology
OSV-2023-877 https://osv.dev/OSV-2023-877 libbpf 1.5.0 1.5.0 1.5.0 libbpf 2023A0000000877 err_not_vulnerable_based_on_repology
MAL-2022-6425 https://osv.dev/MAL-2022-6425 tbb 2021.11.0 2022A0000006425 err_missing_repology_version
MAL-2022-4301 https://osv.dev/MAL-2022-4301 libidn2 2.3.7 2.3.7 2.3.7 libidn2 2022A0000004301 err_not_vulnerable_based_on_repology
OSV-2021-777 https://osv.dev/OSV-2021-777 libxml2 2.13.5 2.13.5 2.13.6 libxml2 2021A0000000777 err_not_vulnerable_based_on_repology
RUSTSEC-2019-0006 https://osv.dev/RUSTSEC-2019-0006 ncurses 6.4.20221231 6.5 6.5 ncurses 2019A0000000006 err_not_vulnerable_based_on_repology
CVE-2016-2781 https://nvd.nist.gov/vuln/detail/CVE-2016-2781 coreutils 6.5 9.5 9.6 9.6 coreutils 2016A0000002781 fix_not_available

@daniel-noland daniel-noland merged commit ff9fe4c into main Feb 25, 2025
4 checks passed
@daniel-noland daniel-noland deleted the pr/daniel-noland/revert-sec-fix branch February 25, 2025 01:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant