Nixpkgs CVEs, LuCI XSS, and Fedora F46 process debates
Security filings in Nixpkgs and an OpenWrt theme thread drove the day, alongside Fedora process and toolchain proposals for F46. Several high-severity local and remote issues moved into packaging trackers with limited discussion so far.
util-linux libmount privilege escalation
Nixpkgs is tracking a CVSS 8.5 local privilege escalation in util-linux libmount that occurs via a failed mount helper. The issue sits in the security tracker for packaging action. Systems that rely on libmount for privileged mount paths have a clear reason to watch for updated packages.
LuCI Footstrap theme reveals stored SVG XSS
A new LuCI theme called Footstrap, described as twice as fast as Bootstrap, prompted a large OpenWrt forum thread that also disclosed stored unauthenticated SVG XSS through wallpaper upload served as image/svg+xml. Dozens of participants joined the discussion. Operators of LuCI interfaces should treat the wallpaper upload path as an exposure until it is fixed.
Immich shared album ownership takeover
Nixpkgs linked CVE-2026-59258 for Immich before 3.0.3, covering shared album editor ownership takeover via updateUser. The security tracker issue is open so packaging can respond. Self-hosters who share album editor rights have a direct incentive to move once fixed packages appear.
Omniflake aggregates twelve thousand flakes
Omniflake was presented as an aggregator that places about twelve thousand GitHub flakes behind one input. Early NixOS Discourse users reported large lockfile reductions and fewer rate-limit problems. The project targets simpler flake dependency management at scale.
Fedora F46 Changes discussion limited to devel list
Fedora proposed that F46 Change discussion occur only on the devel mailing list, with Discourse held to read-only announcements. The thread drew roughly 170 messages from dozens of participants and centered on platform usability. The decision will shape how contributors take part in the Changes process.
ConvertX arbitrary file read via LaTeX
The Nixpkgs security tracker recorded CVE-2026-85618, a high-severity arbitrary file read in ConvertX 0.17.0 through LaTeX input directives. No further discussion has appeared yet. Packagers and ConvertX users should watch for a corrected release.
Aider RCE through configuration file
Nixpkgs opened tracking for CVE-2026-85674, an 8.5 remote code execution in aider 0.86.2 via .aider.conf.yml. The bot-filed issue awaits packaging work. Developers who run aider should treat untrusted configuration files as a risk.
Fedora thin LTO build flag proposal
A self-contained F46 change proposal would switch GCC builds from fat to thin LTO objects to reduce memory use and build time. Devel-list discussion covered terminology, defaults, and .a and .o compatibility. The change is aimed at the next Fedora release cycle.