09325d24b6
This mitigates CVE-2023-4911, crucially without a mass-rebuild. We drop insecure environment variables explicitly, including glibc-specific ones, since musl doesn't do this by default. Change-Id: I591a817e6d4575243937d9ccab51c23a96bed6f9 |
||
---|---|---|
.. | ||
acme | ||
apparmor | ||
wrappers | ||
apparmor.nix | ||
audit.nix | ||
auditd.nix | ||
ca.nix | ||
chromium-suid-sandbox.nix | ||
dhparams.nix | ||
doas.nix | ||
duosec.nix | ||
google_oslogin.nix | ||
ipa.nix | ||
lock-kernel-modules.nix | ||
misc.nix | ||
oath.nix | ||
pam_mount.nix | ||
pam_usb.nix | ||
pam.nix | ||
please.nix | ||
polkit.nix | ||
rngd.nix | ||
rtkit.nix | ||
sudo-rs.nix | ||
sudo.nix | ||
systemd-confinement.nix | ||
tpm2.nix |