Skip to content
All distributions

Updated 20:01

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

503

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

530 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
OpenHighPostgreSQL 'internal' type confusion enables arbitrary OS code execution by any userAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL pltcl/plperl 32-bit integer wraparound causes OOB write, potential RCE; pre-18.5 affectedAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL regexp heap overflow enables OS-level RCE via invalid-encoding text; pre-18.5/17.11/16.15/15.19/14.24 affectedAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL stack buffer overflow in argument name matching via OUT parameter countAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL plperl tied-hash return heap overflow enables OS code execution; affects pre 18.5/17.11/16.15/15.19/14.24Aug 25, 2026Sep 9, 2026
OpenHighPostgreSQL portal/cursor type confusion permits arbitrary code execution as database OS user pre-18.5/17.11/16.15/15.19/14.24Aug 25, 2026Sep 9, 2026
OpenHighType confusion in PostgreSQL ctid selectivity estimator enables memory disclosure via crafted non-ctid inputAug 25, 2026Sep 9, 2026
OpenHighpg_restore_attribute_stats type confusion lets object creators execute OS code in PostgreSQL 18 before 18.5Aug 25, 2026Sep 9, 2026
OpenHighLogical decoding lacks authorization, REPLICATION users can dlopen arbitrary files, execute code as server accountAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL pg_dump heap buffer overflow via crafted long transform lists enables OS user RCEAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL refint type confusion allows arbitrary code execution as DB OS user (pre-18.5/17.11/16.15/15.19/14.24)Aug 25, 2026Sep 9, 2026
OpenHighPostgreSQL pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict expansion; CVE-2025-8714 bypassAug 25, 2026Sep 9, 2026
OpenHighSecurity: psql COPY FROM STDIN may execute data rows as commands on failureAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL EXTRACT() deparse SQL injection lets object owners escalate to superuser via deparse consumersAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL tsvector/tsquery integer wraparound enables unprivileged OOB write and potential RCEAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein/levenshtein_less_equal extreme inputsAug 25, 2026Sep 9, 2026
OpenHighPostgreSQL to_char(timestamptz) heap overflow via long POSIX timezone allows OS-user RCEAug 25, 2026Sep 9, 2026
OpenMediumPostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24Aug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL RLS cache invalidation bug allows unauthorized access after role/ownership changes via plan reuseAug 25, 2026Oct 9, 2026
OpenMediumconfigparser CR in multiline values allows injected keys/values via attacker-controlled inputAug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL 16–18: SCRAM iteration-count discrepancy enables unauthenticated user enumerationAug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL pgcrypto disabled OpenSSL ciphers leak plaintext; wrong-key decryption bypasses MDCAug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL pg_trgm picksplit heap buffer over-read may leak memory via split choicesAug 25, 2026Oct 9, 2026
OpenMediumPostgreSQL DDL lacks auth for range subtype/expressions, enabling DoS on type ALTER/DROPAug 25, 2026Oct 9, 2026
OpenLowPostgreSQL ALTER TABLE ALTER TYPE misassigns stats ownership, allowing unauthorized DROP/ALTERAug 25, 2026Nov 23, 2026
OpenLowPostgreSQL amcheck untrusted search_path permits arbitrary function execution via expression indexes in versions before 18.5/16.15/15.19/14.24Aug 25, 2026Nov 23, 2026
OpenLowPostgreSQL ECPG integer underflow: client DoS via missing bytea prefix; pre-18.5/17.11/16.15/15.19/14.24Aug 25, 2026Nov 23, 2026
Fixed within SLAHighUse-after-free in ieee80211_prepare_and_rx_handle from mesh skb->cb reuse during fast-RXAug 25, 2026Sep 9, 2026Aug 27, 20262 days
Fixed within SLAMediumHDF5 NULL pointer dereference on reading attribute with invalid variable-length datatype fieldAug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumHDF5 h5repack double free when parsing oversized chunk size in crafted fileAug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAMediumHeap-based buffer overflow in HDF5 <=2.1.1 SOHM list-index deserialization (DoS)Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAHighV8 type confusion in Chrome pre-151.0.7922.169 enables sandboxed RCE via crafted HTMLAug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome Android ANGLE buffer overflow before 151.0.7922.169 enables out-of-sandbox RCEAug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighUse-after-free in Chrome WebGL pre-151.0.7922.169 allows sandboxed RCE via crafted HTML pageAug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome <151.0.7922.169 USB race leads to sandbox escape RCE from crafted HTMLAug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighIncorrect calculation in V8 allows sandboxed RCE via crafted HTML in Chrome <151.0.7922.169Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLALowChrome GPU uninitialized resource allows memory read outside sandbox post-renderer compromise (pre-151.0.7922.169)Aug 25, 2026Nov 23, 2026Aug 25, 2026same day
Fixed within SLAMediumHigh-severity Skia info leak in Chrome <151.0.7922.169 allows origin policy bypass via crafted HTMLAug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLAHighHigh-severity Chrome Mac Browser use-after-free pre-151.0.7922.169 allows RCE outside sandbox via crafted HTMLAug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAMediumChrome Android Core reference resolution bug leaks sensitive data via crafted HTML (pre-151.0.7922.169)Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome V8 type confusion allows sandboxed RCE via crafted HTML pre-151.0.7922.169Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHighChrome Windows CredentialProvider link-following bug allows local arbitrary code execution outside sandbox pre-151.0.7922.169Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLACriticalChrome Android Dawn buffer overflow enables remote code execution outside sandbox pre-151.0.7922.169 via crafted HTMLAug 25, 2026Sep 1, 2026Aug 25, 2026same day
Fixed within SLAHighCritical WebGL buffer overflow in Chrome <151.0.7922.169 enables sandbox-escape RCE via crafted HTMLAug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAMediumCORS implementation flaw lets compromised renderer bypass Chrome site isolation (pre-151.0.7922.169)Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLAHighKVM guest_memfd uses signed offset/size; sum overflow bypasses memslot binding file-size checkAug 19, 2026Sep 3, 2026Aug 19, 2026same day
Fixed within SLACriticalLinux kernel netfs potential tearing in remote_i_size/zero_point risking i_size_seqcount corruptionAug 19, 2026Aug 26, 2026Aug 19, 2026same day
Fixed within SLAMediumnetfs_release_folio zero_point misupdate when i_size > remote_i_size causes short readsAug 19, 2026Oct 3, 2026Aug 19, 2026same day
Fixed within SLAMediumReference leak in drm/msm/adreno a6xx_gpu_init from of_parse_phandle early-return pathsAug 19, 2026Oct 3, 2026Aug 19, 2026same day
Fixed within SLAMediumERoFS inode xattr init: metabuf/folio ref leak on error paths after erofs_read_metabufAug 19, 2026Oct 3, 2026Aug 19, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems