Updated 22:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Open | High | PostgreSQL 'internal' type confusion enables arbitrary OS code execution by any user | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL pltcl/plperl 32-bit integer wraparound causes OOB write, potential RCE; pre-18.5 affected | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL regexp heap overflow enables OS-level RCE via invalid-encoding text; pre-18.5/17.11/16.15/15.19/14.24 affected | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL stack buffer overflow in argument name matching via OUT parameter count | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL plperl tied-hash return heap overflow enables OS code execution; affects pre 18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL portal/cursor type confusion permits arbitrary code execution as database OS user pre-18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | Type confusion in PostgreSQL ctid selectivity estimator enables memory disclosure via crafted non-ctid input | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | pg_restore_attribute_stats type confusion lets object creators execute OS code in PostgreSQL 18 before 18.5 | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | Logical decoding lacks authorization, REPLICATION users can dlopen arbitrary files, execute code as server account | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL pg_dump heap buffer overflow via crafted long transform lists enables OS user RCE | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL refint type confusion allows arbitrary code execution as DB OS user (pre-18.5/17.11/16.15/15.19/14.24) | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict expansion; CVE-2025-8714 bypass | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | Security: psql COPY FROM STDIN may execute data rows as commands on failure | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL EXTRACT() deparse SQL injection lets object owners escalate to superuser via deparse consumers | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL tsvector/tsquery integer wraparound enables unprivileged OOB write and potential RCE | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein/levenshtein_less_equal extreme inputs | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | High | PostgreSQL to_char(timestamptz) heap overflow via long POSIX timezone allows OS-user RCE | Aug 25, 2026 | Sep 9, 2026 | — | — | |
| Open | Medium | PostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL RLS cache invalidation bug allows unauthorized access after role/ownership changes via plan reuse | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | configparser CR in multiline values allows injected keys/values via attacker-controlled input | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL 16–18: SCRAM iteration-count discrepancy enables unauthenticated user enumeration | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL pgcrypto disabled OpenSSL ciphers leak plaintext; wrong-key decryption bypasses MDC | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL pg_trgm picksplit heap buffer over-read may leak memory via split choices | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Medium | PostgreSQL DDL lacks auth for range subtype/expressions, enabling DoS on type ALTER/DROP | Aug 25, 2026 | Oct 9, 2026 | — | — | |
| Open | Low | PostgreSQL ALTER TABLE ALTER TYPE misassigns stats ownership, allowing unauthorized DROP/ALTER | Aug 25, 2026 | Nov 23, 2026 | — | — | |
| Open | Low | PostgreSQL amcheck untrusted search_path permits arbitrary function execution via expression indexes in versions before 18.5/16.15/15.19/14.24 | Aug 25, 2026 | Nov 23, 2026 | — | — | |
| Open | Low | PostgreSQL ECPG integer underflow: client DoS via missing bytea prefix; pre-18.5/17.11/16.15/15.19/14.24 | Aug 25, 2026 | Nov 23, 2026 | — | — | |
| Fixed within SLA | High | Use-after-free in ieee80211_prepare_and_rx_handle from mesh skb->cb reuse during fast-RX | Aug 25, 2026 | Sep 9, 2026 | Aug 27, 2026 | 2 days | |
| Fixed within SLA | Medium | HDF5 NULL pointer dereference on reading attribute with invalid variable-length datatype field | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | HDF5 h5repack double free when parsing oversized chunk size in crafted file | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | Medium | Heap-based buffer overflow in HDF5 <=2.1.1 SOHM list-index deserialization (DoS) | Aug 25, 2026 | Oct 9, 2026 | Aug 26, 2026 | 1 day | |
| Fixed within SLA | High | V8 type confusion in Chrome pre-151.0.7922.169 enables sandboxed RCE via crafted HTML | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome Android ANGLE buffer overflow before 151.0.7922.169 enables out-of-sandbox RCE | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome WebGL pre-151.0.7922.169 allows sandboxed RCE via crafted HTML page | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.169 USB race leads to sandbox escape RCE from crafted HTML | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Incorrect calculation in V8 allows sandboxed RCE via crafted HTML in Chrome <151.0.7922.169 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Low | Chrome GPU uninitialized resource allows memory read outside sandbox post-renderer compromise (pre-151.0.7922.169) | Aug 25, 2026 | Nov 23, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Medium | High-severity Skia info leak in Chrome <151.0.7922.169 allows origin policy bypass via crafted HTML | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | High-severity Chrome Mac Browser use-after-free pre-151.0.7922.169 allows RCE outside sandbox via crafted HTML | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android Core reference resolution bug leaks sensitive data via crafted HTML (pre-151.0.7922.169) | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 type confusion allows sandboxed RCE via crafted HTML pre-151.0.7922.169 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Chrome Windows CredentialProvider link-following bug allows local arbitrary code execution outside sandbox pre-151.0.7922.169 | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Android Dawn buffer overflow enables remote code execution outside sandbox pre-151.0.7922.169 via crafted HTML | Aug 25, 2026 | Sep 1, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | Critical WebGL buffer overflow in Chrome <151.0.7922.169 enables sandbox-escape RCE via crafted HTML | Aug 25, 2026 | Sep 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | Medium | CORS implementation flaw lets compromised renderer bypass Chrome site isolation (pre-151.0.7922.169) | Aug 25, 2026 | Oct 9, 2026 | Aug 25, 2026 | same day | |
| Fixed within SLA | High | KVM guest_memfd uses signed offset/size; sum overflow bypasses memslot binding file-size check | Aug 19, 2026 | Sep 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Critical | Linux kernel netfs potential tearing in remote_i_size/zero_point risking i_size_seqcount corruption | Aug 19, 2026 | Aug 26, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Medium | netfs_release_folio zero_point misupdate when i_size > remote_i_size causes short reads | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Medium | Reference leak in drm/msm/adreno a6xx_gpu_init from of_parse_phandle early-return paths | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | Medium | ERoFS inode xattr init: metabuf/folio ref leak on error paths after erofs_read_metabuf | Aug 19, 2026 | Oct 3, 2026 | Aug 19, 2026 | same day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.