← All distributions
Updated 23:01
Determinate Secure Packages distribution
secure-packages-25.11SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS plannedPackages are not yet available in a FIPS-compliant variant, but we plan to release one.Until May 2028Covered until May 2028. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 25.11. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
172
last 30 days
Fixed within SLA
2
last 7 days
Open
28
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-25.11/0";
}200 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Chrome DevTools insufficient input validation lets remote attackers bypass navigation restrictions via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Views on Linux Chrome <151.0.7922.72 allows remote heap corruption via crafted HTML | Aug 5, 2026 | Aug 20, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | High | Linux Chrome Chromoting pre-151.0.7922.72 allows local privilege escalation via network traffic | Aug 4, 2026 | Aug 19, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | Medium | Chrome Android GPU side-channel lets remote attackers leak cross-origin data before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Cast pre-151.0.7922.72 remote cross-origin data leak via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome CSS bug enabled remote script/HTML injection (UXSS) before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | GetUserMedia allows cross-origin data leak in Chrome prior to 151.0.7922.72 via compromised renderer | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Credential Management UI spoofing via crafted HTML by remote attacker pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Payments input validation bug enables UI spoofing by compromised renderer pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 insufficient input validation enables remote navigation restriction bypass | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Blink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome DevTools same-origin policy bypass via crafted HTML before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | High | Insufficient validation in Chrome DevTools allows extension-based privilege escalation pre-151.0.7922.72 | Aug 5, 2026 | Aug 20, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | High | Chrome Mac Audio use-after-free enables sandbox escape after renderer compromise via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Aug 20, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Loader before 151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Incorrect security UI allows Omnibox spoofing via crafted HTML on Chrome iOS <151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Isolated Web Apps in Chrome <151.0.7922.72 allow remote bypass of navigation restrictions via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Remote Site Isolation bypass in Google Chrome <151.0.7922.72 via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Autofill cross-origin data leak via crafted HTML page pre-151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Policy bypass in Chrome Receiver enables sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Inappropriate PresentationAPI implementation leaks cross-origin data in Chrome before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | High | Insufficient input validation in Chrome Variations enables heap corruption by privileged network attacker | Aug 5, 2026 | Aug 20, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Cast insufficient input validation (<151.0.7922.72) leaks cross-origin data via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 WebGL out-of-bounds read allows remote memory disclosure via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Skia uninitialized use enables cross-origin data leak via crafted HTML in Chrome <151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Mac pre-151.0.7922.72 Media OOB read enables sandbox escape after renderer compromise | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Cast input validation flaw leaks cross-origin data via crafted HTML (pre-151.0.7922.72) (Medium severity) | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Critical | Chrome WebSockets input validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72) | Aug 5, 2026 | Aug 12, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient WebView input validation in Android Chrome leaks cross-origin data after renderer compromise | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome FedCM same-origin policy bypass by remote attacker via crafted HTML prior to 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome on iOS before 151.0.7922.72 leaks cross-origin data via crafted HTML page | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72 UXSS via insufficient validation of untrusted network input | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient policy enforcement in Chrome Presentation pre-151.0.7922.72 allows remote navigation bypass via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Extensions security UI flaw enables UI spoofing via crafted extension | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | Medium | Blink SOP bypass via crafted HTML in Chrome before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 5, 2026 | same day | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 ADX decoder OOB read/write on mid-stream channel layout change | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS on crafted stream | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_size | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 NVDEC nvdec.c double-free allows memory corruption via crafted video | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack buffer overflow via oversized vps_num_hrd_parameters causing RCE | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | FFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via crafted .sub/.idx stream IDs | Jul 29, 2026 | Aug 13, 2026 | Aug 5, 2026 | 7 days | |
| Fixed within SLA | High | powerpc/pgtable-frag: pte_frag_destroy leaves folio active, causing bad page state on exit | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | High | BPF verifier miscomputes delta when src==dst, causing linked reg verifier-vs-runtime mismatch | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | High | Offloaded BPF map/prog info query triggers UAF via get_net during netns teardown | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | High | AMD DRM: Out-of-bounds read in dp_get_eq_aux_rd_interval with 8 LTTPR repeaters | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | High | Linux vdpa: Unlocked driver_override access during __driver_attach() match() causes UAF | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | High | BPF verifier fails to simulate ld_{abs,ind} subprog failure path causing unsafe returns | Jul 27, 2026 | Aug 11, 2026 | Jul 30, 2026 | 3 days | |
| Fixed within SLA | High | BPF sock_ops dst==src macro bug causes OOB read and kernel pointer leak | Jul 23, 2026 | Aug 7, 2026 | Jul 30, 2026 | 7 days | |
| Fixed within SLA | High | Greybus gb_raw use-after-free on write after disconnect triggers kernel panic | Jul 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 13 days |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.