Skip to content
All distributions

Updated 03:00

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

479

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

506 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLACriticalChrome Mac ANGLE flaw allows remote sandbox escape via crafted HTML pre-151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighGoogle Chrome prior to 151.0.7922.72 DOM use-after-free enables sandboxed RCE via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome <151.0.7922.72 FileSystem policy flaw enables remote cross-origin data leak via crafted pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalUse-after-free in DataTransfer enables sandbox escape via crafted HTML in Chrome <151.0.7922.72 on WindowsAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalOut-of-bounds write in ANGLE enables remote sandbox escape in Chrome Windows pre-151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android PDF input validation flaw allows local cross-origin data leak via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumHigh-severity ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome <151.0.7922.72 Input use-after-free allows renderer sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalANGLE type confusion in Chrome <151.0.7922.72 enables sandbox escape via crafted HTML after renderer compromiseAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Passwords untrusted input validation flaw allows site isolation bypass pre-151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Autofill use-after-free enables sandboxed RCE via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome for iOS <151.0.7922.72: Insufficient input validation enables renderer sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumANGLE implementation flaw leaks process memory via crafted HTML in Chrome <151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalANGLE integer overflow in Chrome <151.0.7922.72 enables post-renderer sandbox escapeAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Android WebAuthn input validation flaw enables renderer-compromised sandbox escape via crafted HTML pre-151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome on ChromeOS Color heap buffer overflow enables sandbox escape via HTML, renderer compromise pre-151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome Print Preview validation flaw leaks cross-origin data via renderer compromiseAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome ANGLE out-of-bounds read enables renderer sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighRemote sandbox escape via crafted HTML in Chrome Android ANGLE pre-151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalANGLE bug enables post-renderer-compromise sandbox escape via crafted HTML in Chrome Android <151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalANGLE out-of-bounds write enables sandbox escape via crafted HTML in Chrome <151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalPre-151.0.7922.72 Chrome QUIC integer overflow enables sandbox escape from compromised renderer via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalChromecast input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72)Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome ANGLE input validation bug allows sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalUse-after-free in Chrome Views allows sandbox escape via crafted HTML from compromised rendererAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticaliOS Chrome <151.0.7922.72 allows remote sandbox escape via crafted HTML pageAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 ANGLE uninitialized use leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumRemote cross-origin data leak via crafted HTML exploiting ANGLE uninitialized use in Chrome <151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Enterprise <151.0.7922.72 crypto bug allows discretionary access control bypass via network MITMAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighHigh-severity Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Android GPU input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalInsufficient input validation in Chrome Android Dawn allows remote sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighFFmpeg 4.4–8.1.2 ADX decoder OOB on mid-stream channel layout changeJul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAHighFFmpeg RTP/ASF demuxer infinite loop DoS via undersized chunk in rtp_asf_fix_headerJul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAHighFFmpeg S/PDIF muxer out-of-bounds read via crafted DTS core_size during remuxingJul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAHighFFmpeg 4.4–8.1.2 NVDEC double-free causes memory corruption with crafted videosJul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAHighFFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack overflow via crafted bitstream enabling RCEJul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAHighFFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via excessive subtitle stream IDs (RCE)Jul 29, 2026Aug 13, 2026Aug 4, 20266 days
Fixed within SLAHighIPv4 __ip_append_data paged allocation misaccounts fraggap causing undersized linear area, overstated pagedlenJul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAHighIPv6 paged path fraggap misaccounting overflows skb via UDPv6 MSG_MORE/MSG_SPLICE_PAGESJul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAHighaf_unix race: unix_gc may run with gc_in_progress=false, breaking MSG_PEEK handlingJul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAHighKVM x86 UAF: role mismatch reuses shadow page after PDE split 2MB→4KB; rmap not removedJul 23, 2026Aug 7, 2026Aug 4, 202612 days
Fixed within SLAHighHeap overflow in BusyBox 1.38.0 shell/ash.c evalcommand() enables DoS via crafted inputAug 4, 2026Aug 4, 2026Aug 4, 2026same day
Fixed within SLAHighHeap overflow in BusyBox 1.38.0 shell/ash.c ifsbreakup() enabling DoS via crafted inputAug 4, 2026Aug 4, 2026Aug 4, 2026same day
Fixed within SLAHighBusyBox 1.38.0 awk_sub() use-after-free in editors/awk.c enables DoS via crafted AWK scriptAug 4, 2026Aug 4, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Greybus raw cdev on close after bundle disconnect causes panicJul 20, 2026Aug 4, 2026Jul 30, 202610 days
Fixed within SLAHighLinux Greybus raw: use-after-free on write after disconnect triggers kernel panicJul 20, 2026Aug 4, 2026Jul 30, 202610 days
Fixed within SLAHighLinux ice driver double-free of skb during tx ring cleanup after TSO/CSUM failureJul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLAHighNetfilter nf_tables: netlink dump race from non-RCU hook list joins during commitJul 16, 2026Jul 31, 2026Jul 30, 202614 days
Fixed within SLAHighceph: Missing folio_put for writeback-ineligible folios removed from batch causes reference leakJul 16, 2026Jul 31, 2026Jul 30, 202614 days

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems