diff options
| author | Jörg Thalheim <joerg@thalheim.io> | 2025-06-22 18:50:46 +0200 |
|---|---|---|
| committer | Jörg Thalheim <joerg@thalheim.io> | 2025-06-24 16:11:11 +0200 |
| commit | 639ad310605baa85093cdb0692759aedaaa02780 (patch) | |
| tree | 06c8935ea39e530c8eaedc0b023e60c29227c4cc /pkgs/development/python-modules/rangehttpserver | |
| parent | 3d27c5f2485588fd7f61eb2e0ead168d2b94addc (diff) | |
nix_2_26: add patch for GHSA-g948-229j-48j3
This addresses a TOCTOU (Time-of-Check to Time-of-Use) vulnerability in Nix's
build system that could potentially allow privilege escalation or unauthorized
file access during the build process.
The patch includes:
- Safe file operations using file descriptors
- Secure temporary directory handling
- Safe chown operations
- PassAsFile security improvements
- Path validation fixes
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions
