We’re rolling out an important Kanidm security fix for SelfPrivacy servers tomorrow. (https://github.com/kanidm/kanidm/security/advisories/GHSA-xxwr-vvr3-2g9f) This vulnerability can only be exploited by users of your server that you've created in the "Users" tab. Unauthenticated users cannot do that.
If automatic updates are enabled, your server will update normally.
If you have automatic updates turned off, please run a server update in the SelfPrivacy app as soon as possible so your server receives the NixOS configuration update needed to use our binary cache and apply the Kanidm fix faster. Otherwise your server will have to rebuild Kanidm from sources, which will likely fail due to memory constraints.
We're shipping the fix ourselves instead of waiting for nixpkgs upstream due to severity of the issue. We've already done this before, because it usually takes several days for nixpkgs to release new versions. This time we've added our own binary cache with pre-built packages, because building Kanidm requires at least 4 cores, 16GB+ of RAM, and over 4 hours of time. Most of the SelfPrivacy deployments would just crash trying to compile it.
This cache will also speed up rebuilds overall, because it includes other services that your server has to compile on its own, like Vikunja or our own server-side components.
Side note about recent Linux kernel vulnerabilities in the news: SelfPrivacy instances are not affected, because they use a hardened Linux profile. It will be dropped in the next NixOS release, so we will continue maintaining it ourselves. But in any case, reboot your server from time to time to ensure you're running on the latest kernel.