← All distributions
Updated 20:01
Determinate Secure Packages distribution
secure-packages-25.11SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS plannedPackages are not yet available in a FIPS-compliant variant, but we plan to release one.Until May 2028Covered until May 2028. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 25.11. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
172
last 30 days
Fixed within SLA
2
last 7 days
Open
28
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-25.11/0";
}200 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Open | High | PostgreSQL tsvector/tsquery integer wraparound causes OOB write RCE; affects <18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL portal/cursor type confusion enables arbitrary OS-level code execution; before 18.5/17.11/16.15/15.19/14.24. | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | psql COPY FROM STDIN may execute data rows as commands on early failure | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL EXTRACT() deparse SQL injection lets object owners run superuser SQL; affects pg_dump and psql | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL regexp heap overflow permits RCE via invalid encoding; pre-18.5/17.11/16.15/15.19/14.24 affected | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | Heap buffer overflow in PostgreSQL plperl tied hash return enables function owner OS code execution | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | Restore-time code execution via psql \restrict/\unrestrict in PostgreSQL pg_dump/pg_dumpall/pg_restore | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein; affects versions before 18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | Heap overflow in PostgreSQL to_char(timestamptz) enables code execution via long timezone abbreviation | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | pg_dump heap overflow on long transform lists enables RCE; PostgreSQL <18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | Type confusion in PostgreSQL 'internal' arguments enables arbitrary code execution by any user via functions | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | mac80211 use-after-free: fast-RX reads RX status after mesh forwarding reuses skb->cb | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory data (pre-18.5/17.11/16.15/15.19/14.24) | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL 32-bit pltcl/plperl integer wraparound enables OOB write and RCE (pre-18.5/17.11/16.15/15.19/14.24) | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL 18.0-18.4 pg_restore_attribute_stats type confusion enables OS-level code execution via range/multirange | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL logical decoding auth flaw lets REPLICATION users dlopen arbitrary files, execute code | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL refint type confusion enables arbitrary code execution as DB OS user; affects <18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL stack buffer overflow via OUT parameter count in argument name matching; 0x0/0x1 writes | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | Medium | PostgreSQL stale RLS policies after role or ownership changes due to plan reuse | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL ascii() buffer over-read leaks up to 3 bytes via crafted text; affects <18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL pgcrypto vuln: disabled ciphers allow cleartext recovery, wrong-key decryption bypasses MDC | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | SCRAM auth iteration-count discrepancy enables user enumeration with non-default scram_iterations; affects PostgreSQL 16–18 pre 18.5/17.11/16.15 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | ConfigParser write() allows key/value injection via CR in attacker-controlled multiline values | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL pg_trgm picksplit buffer over-read enabling memory inference; affects pre-18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL DDL missing auth enables DoS on type ALTER/DROP via range/expression dependencies | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Low | PostgreSQL amcheck untrusted search_path enables privilege escalation via expression indexes; affects <18.5/16.15/15.19/14.24 | Aug 25, 2026 | Nov 23, 2026 | — | — | |
| Open | Low | PostgreSQL ALTER TABLE ALTER TYPE reassigns stats ownership, enabling unauthorized DROP/ALTER; pre-18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Nov 23, 2026 | — | — | |
| Open | Low | Server-admin triggered PostgreSQL ECPG integer underflow DoS via malformed bytea; pre-18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Nov 23, 2026 | — | — | |
| Fixed within SLA | Medium | HDF5 h5repack double free on crafted file with oversized chunk size | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | HDF5 <=2.1.1 SOHM list-index deserialization heap overflow via crafted file, causing crash | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | GStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoS | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | Heap OOB read/write and leak via FUJIFILM strd underflow in GStreamer avidemux | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Critical | Netfs: Tearing in remote_i_size/zero_point may corrupt i_size_seqcount | Aug 18, 2026 | Aug 25, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | netfs_release_folio zero_point update uses i_size not remote_i_size, causing EOF short reads | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | Reference leak in a6xx_gpu_init() due to missed of_node_put on early error paths | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | Medium | ERoFS inode xattr init error paths leak metabuf, causing folio reference leak | Aug 18, 2026 | Oct 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Blink use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.137 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.137 HTML use-after-free enables sandboxed remote code execution via crafted page | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed code execution via malicious extension | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Google Chrome Mac TabStrip use-after-free enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.137) | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | High-severity V8 use-after-free in Chrome <151.0.7922.137 enables sandboxed RCE via crafted HTML | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | KVM guest_memfd offset+size treated signed, letting negative sum bypass file size check | Aug 17, 2026 | Sep 1, 2026 | Aug 18, 2026 | 1 day | |
| Fixed within SLA | Critical | UAF in netfs_unlock_abandoned_read_pages and netfs_unlock_read_folio after request progress cleared | Aug 12, 2026 | Aug 19, 2026 | Aug 18, 2026 | 6 days | |
| Fixed within SLA | Medium | Arithmetic overflow in af_alg AEAD AD length leads to TX buffer size miscalculation | Jul 16, 2026 | Aug 30, 2026 | Aug 17, 2026 | 32 days | |
| Fixed within SLA | Medium | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days | ||
| Fixed within SLA | Medium | Jul 8, 2026 | Aug 22, 2026 | Aug 17, 2026 | 40 days |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.