Skip to content
All distributions

Updated 22:00

Determinate Secure Packages distribution

secure-packages-25.11SupportedFIPS plannedUntil May 2028

Built on Nixpkgs 25.11. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

172

last 30 days

Fixed within SLA

2

last 7 days

Open

28

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-25.11/0";
}

200 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
OpenHighPostgreSQL tsvector/tsquery integer wraparound causes OOB write RCE; affects <18.5/17.11/16.15/15.19/14.24Aug 25, 2026Sep 9, 2026
OpenHighPostgreSQL portal/cursor type confusion enables arbitrary OS-level code execution; before 18.5/17.11/16.15/15.19/14.24.Aug 25, 2026Sep 9, 2026
OpenHighpsql COPY FROM STDIN may execute data rows as commands on early failureAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL EXTRACT() deparse SQL injection lets object owners run superuser SQL; affects pg_dump and psqlAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL regexp heap overflow permits RCE via invalid encoding; pre-18.5/17.11/16.15/15.19/14.24 affectedAug 25, 2026Sep 9, 2026
OpenHighHeap buffer overflow in PostgreSQL plperl tied hash return enables function owner OS code executionAug 25, 2026Sep 9, 2026
OpenHighRestore-time code execution via psql \restrict/\unrestrict in PostgreSQL pg_dump/pg_dumpall/pg_restoreAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein; affects versions before 18.5/17.11/16.15/15.19/14.24Aug 25, 2026Sep 9, 2026
OpenHighHeap overflow in PostgreSQL to_char(timestamptz) enables code execution via long timezone abbreviationAug 25, 2026Sep 9, 2026
OpenHighpg_dump heap overflow on long transform lists enables RCE; PostgreSQL <18.5/17.11/16.15/15.19/14.24Aug 25, 2026Sep 9, 2026
OpenHighType confusion in PostgreSQL 'internal' arguments enables arbitrary code execution by any user via functionsAug 25, 2026Sep 9, 2026
OpenHighmac80211 use-after-free: fast-RX reads RX status after mesh forwarding reuses skb->cbAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory data (pre-18.5/17.11/16.15/15.19/14.24)Aug 25, 2026Sep 9, 2026
OpenHighPostgreSQL 32-bit pltcl/plperl integer wraparound enables OOB write and RCE (pre-18.5/17.11/16.15/15.19/14.24)Aug 25, 2026Sep 9, 2026
OpenHighPostgreSQL 18.0-18.4 pg_restore_attribute_stats type confusion enables OS-level code execution via range/multirangeAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL logical decoding auth flaw lets REPLICATION users dlopen arbitrary files, execute codeAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL refint type confusion enables arbitrary code execution as DB OS user; affects <18.5/17.11/16.15/15.19/14.24Aug 25, 2026Sep 9, 2026
OpenHighPostgreSQL stack buffer overflow via OUT parameter count in argument name matching; 0x0/0x1 writesAug 25, 2026Sep 9, 2026
OpenMediumPostgreSQL stale RLS policies after role or ownership changes due to plan reuseAug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL ascii() buffer over-read leaks up to 3 bytes via crafted text; affects <18.5/17.11/16.15/15.19/14.24Aug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL pgcrypto vuln: disabled ciphers allow cleartext recovery, wrong-key decryption bypasses MDCAug 25, 2026Oct 9, 2026
OpenMediumSCRAM auth iteration-count discrepancy enables user enumeration with non-default scram_iterations; affects PostgreSQL 16–18 pre 18.5/17.11/16.15Aug 25, 2026Oct 9, 2026
OpenMediumConfigParser write() allows key/value injection via CR in attacker-controlled multiline valuesAug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL pg_trgm picksplit buffer over-read enabling memory inference; affects pre-18.5/17.11/16.15/15.19/14.24Aug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL DDL missing auth enables DoS on type ALTER/DROP via range/expression dependenciesAug 25, 2026Oct 9, 2026
OpenLowPostgreSQL amcheck untrusted search_path enables privilege escalation via expression indexes; affects <18.5/16.15/15.19/14.24Aug 25, 2026Nov 23, 2026
OpenLowPostgreSQL ALTER TABLE ALTER TYPE reassigns stats ownership, enabling unauthorized DROP/ALTER; pre-18.5/17.11/16.15/15.19/14.24Aug 25, 2026Nov 23, 2026
OpenLowServer-admin triggered PostgreSQL ECPG integer underflow DoS via malformed bytea; pre-18.5/17.11/16.15/15.19/14.24Aug 25, 2026Nov 23, 2026
Fixed within SLAMediumHDF5 h5repack double free on crafted file with oversized chunk sizeAug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumHDF5 <=2.1.1 SOHM list-index deserialization heap overflow via crafted file, causing crashAug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumGStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoSAug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAMediumHeap OOB read/write and leak via FUJIFILM strd underflow in GStreamer avidemuxAug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLACriticalNetfs: Tearing in remote_i_size/zero_point may corrupt i_size_seqcountAug 18, 2026Aug 25, 2026Aug 19, 20261 day
Fixed within SLAMediumnetfs_release_folio zero_point update uses i_size not remote_i_size, causing EOF short readsAug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAMediumReference leak in a6xx_gpu_init() due to missed of_node_put on early error pathsAug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAMediumERoFS inode xattr init error paths leak metabuf, causing folio reference leakAug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAHighBlink use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.137Aug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAHighChrome <151.0.7922.137 HTML use-after-free enables sandboxed remote code execution via crafted pageAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAHighUse-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed code execution via malicious extensionAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAHighGoogle Chrome Mac TabStrip use-after-free enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.137)Aug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAHighHigh-severity V8 use-after-free in Chrome <151.0.7922.137 enables sandboxed RCE via crafted HTMLAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAHighKVM guest_memfd offset+size treated signed, letting negative sum bypass file size checkAug 17, 2026Sep 1, 2026Aug 18, 20261 day
Fixed within SLACriticalUAF in netfs_unlock_abandoned_read_pages and netfs_unlock_read_folio after request progress clearedAug 12, 2026Aug 19, 2026Aug 18, 20266 days
Fixed within SLAMediumArithmetic overflow in af_alg AEAD AD length leads to TX buffer size miscalculationJul 16, 2026Aug 30, 2026Aug 17, 202632 days
Fixed within SLAMediumJul 8, 2026Aug 22, 2026Aug 17, 202640 days
Fixed within SLAMediumJul 8, 2026Aug 22, 2026Aug 17, 202640 days
Fixed within SLAMediumJul 8, 2026Aug 22, 2026Aug 17, 202640 days
Fixed within SLAMediumJul 8, 2026Aug 22, 2026Aug 17, 202640 days
Fixed within SLAMediumJul 8, 2026Aug 22, 2026Aug 17, 202640 days
Fixed within SLAMediumJul 8, 2026Aug 22, 2026Aug 17, 202640 days

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems