Skip to content
All distributions

Updated 23:01

Determinate Secure Packages distribution

secure-packages-25.11SupportedFIPS plannedUntil May 2028

Built on Nixpkgs 25.11. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

172

last 30 days

Fixed within SLA

2

last 7 days

Open

28

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-25.11/0";
}

200 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAMediumChrome DevTools insufficient input validation lets remote attackers bypass navigation restrictions via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 5, 20261 day
Fixed within SLAHighUse-after-free in Views on Linux Chrome <151.0.7922.72 allows remote heap corruption via crafted HTMLAug 5, 2026Aug 20, 2026Aug 5, 2026same day
Fixed within SLAHighLinux Chrome Chromoting pre-151.0.7922.72 allows local privilege escalation via network trafficAug 4, 2026Aug 19, 2026Aug 5, 20261 day
Fixed within SLAMediumChrome Android GPU side-channel lets remote attackers leak cross-origin data before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumGoogle Chrome Cast pre-151.0.7922.72 remote cross-origin data leak via crafted HTMLAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumGoogle Chrome CSS bug enabled remote script/HTML injection (UXSS) before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumGetUserMedia allows cross-origin data leak in Chrome prior to 151.0.7922.72 via compromised rendererAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome Credential Management UI spoofing via crafted HTML by remote attacker pre-151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome Payments input validation bug enables UI spoofing by compromised renderer pre-151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome iOS <151.0.7922.72 insufficient input validation enables remote navigation restriction bypassAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumBlink cross-origin data leak via crafted HTML in Chrome before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome DevTools same-origin policy bypass via crafted HTML before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAHighInsufficient validation in Chrome DevTools allows extension-based privilege escalation pre-151.0.7922.72Aug 5, 2026Aug 20, 2026Aug 5, 2026same day
Fixed within SLAMediumANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAHighChrome Mac Audio use-after-free enables sandbox escape after renderer compromise via crafted HTML (pre-151.0.7922.72)Aug 5, 2026Aug 20, 2026Aug 5, 2026same day
Fixed within SLAMediumGoogle Chrome Loader before 151.0.7922.72 leaks cross-origin data via crafted HTMLAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumIncorrect security UI allows Omnibox spoofing via crafted HTML on Chrome iOS <151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumIsolated Web Apps in Chrome <151.0.7922.72 allow remote bypass of navigation restrictions via crafted HTMLAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumRemote Site Isolation bypass in Google Chrome <151.0.7922.72 via crafted HTML pageAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumGoogle Chrome Autofill cross-origin data leak via crafted HTML page pre-151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumPolicy bypass in Chrome Receiver enables sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumInappropriate PresentationAPI implementation leaks cross-origin data in Chrome before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAHighInsufficient input validation in Chrome Variations enables heap corruption by privileged network attackerAug 5, 2026Aug 20, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome Cast insufficient input validation (<151.0.7922.72) leaks cross-origin data via crafted HTMLAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 WebGL out-of-bounds read allows remote memory disclosure via crafted HTMLAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumSkia uninitialized use enables cross-origin data leak via crafted HTML in Chrome <151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome Mac pre-151.0.7922.72 Media OOB read enables sandbox escape after renderer compromiseAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome Cast input validation flaw leaks cross-origin data via crafted HTML (pre-151.0.7922.72) (Medium severity)Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLACriticalChrome WebSockets input validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72)Aug 5, 2026Aug 12, 2026Aug 5, 2026same day
Fixed within SLAMediumInsufficient WebView input validation in Android Chrome leaks cross-origin data after renderer compromiseAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome FedCM same-origin policy bypass by remote attacker via crafted HTML prior to 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumGoogle Chrome on iOS before 151.0.7922.72 leaks cross-origin data via crafted HTML pageAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome iOS <151.0.7922.72 UXSS via insufficient validation of untrusted network inputAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumInsufficient policy enforcement in Chrome Presentation pre-151.0.7922.72 allows remote navigation bypass via crafted HTMLAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 Extensions security UI flaw enables UI spoofing via crafted extensionAug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAMediumBlink SOP bypass via crafted HTML in Chrome before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 5, 2026same day
Fixed within SLAHighFFmpeg 4.4–8.1.2 ADX decoder OOB read/write on mid-stream channel layout changeJul 29, 2026Aug 13, 2026Aug 5, 20267 days
Fixed within SLAHighFFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS on crafted streamJul 29, 2026Aug 13, 2026Aug 5, 20267 days
Fixed within SLAHighFFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_sizeJul 29, 2026Aug 13, 2026Aug 5, 20267 days
Fixed within SLAHighFFmpeg 4.4–8.1.2 NVDEC nvdec.c double-free allows memory corruption via crafted videoJul 29, 2026Aug 13, 2026Aug 5, 20267 days
Fixed within SLAHighFFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack buffer overflow via oversized vps_num_hrd_parameters causing RCEJul 29, 2026Aug 13, 2026Aug 5, 20267 days
Fixed within SLAHighFFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via crafted .sub/.idx stream IDsJul 29, 2026Aug 13, 2026Aug 5, 20267 days
Fixed within SLAHighpowerpc/pgtable-frag: pte_frag_destroy leaves folio active, causing bad page state on exitJul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAHighBPF verifier miscomputes delta when src==dst, causing linked reg verifier-vs-runtime mismatchJul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAHighOffloaded BPF map/prog info query triggers UAF via get_net during netns teardownJul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAHighAMD DRM: Out-of-bounds read in dp_get_eq_aux_rd_interval with 8 LTTPR repeatersJul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAHighLinux vdpa: Unlocked driver_override access during __driver_attach() match() causes UAFJul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAHighBPF verifier fails to simulate ld_{abs,ind} subprog failure path causing unsafe returnsJul 27, 2026Aug 11, 2026Jul 30, 20263 days
Fixed within SLAHighBPF sock_ops dst==src macro bug causes OOB read and kernel pointer leakJul 23, 2026Aug 7, 2026Jul 30, 20267 days
Fixed within SLAHighGreybus gb_raw use-after-free on write after disconnect triggers kernel panicJul 17, 2026Aug 1, 2026Jul 30, 202613 days

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems