diff options
| author | Jörg Thalheim <joerg@thalheim.io> | 2025-06-22 18:50:02 +0200 |
|---|---|---|
| committer | Jörg Thalheim <joerg@thalheim.io> | 2025-06-24 16:11:11 +0200 |
| commit | 3d27c5f2485588fd7f61eb2e0ead168d2b94addc (patch) | |
| tree | 6824edba1fe843c61e733c2f1e90ae724966d9b0 /pkgs/development/python-modules/rangehttpserver | |
| parent | 5ec9d2579382597149f853b3983c01a5f915f322 (diff) | |
nix_2_24: add patch for GHSA-g948-229j-48j3
This addresses a TOCTOU (Time-of-Check to Time-of-Use) vulnerability in Nix's
build system that could potentially allow privilege escalation or unauthorized
file access during the build process.
The patch includes:
- Safe file operations using file descriptors
- Secure temporary directory handling
- Safe chown operations
- PassAsFile security improvements
- Path validation fixes
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions
