Updated 03:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Critical | Chrome Mac ANGLE flaw allows remote sandbox escape via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Google Chrome prior to 151.0.7922.72 DOM use-after-free enables sandboxed RCE via crafted HTML | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome <151.0.7922.72 FileSystem policy flaw enables remote cross-origin data leak via crafted page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in DataTransfer enables sandbox escape via crafted HTML in Chrome <151.0.7922.72 on Windows | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Out-of-bounds write in ANGLE enables remote sandbox escape in Chrome Windows pre-151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android PDF input validation flaw allows local cross-origin data leak via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | High-severity ANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome <151.0.7922.72 Input use-after-free allows renderer sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE type confusion in Chrome <151.0.7922.72 enables sandbox escape via crafted HTML after renderer compromise | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Passwords untrusted input validation flaw allows site isolation bypass pre-151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Autofill use-after-free enables sandboxed RCE via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome for iOS <151.0.7922.72: Insufficient input validation enables renderer sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | ANGLE implementation flaw leaks process memory via crafted HTML in Chrome <151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE integer overflow in Chrome <151.0.7922.72 enables post-renderer sandbox escape | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Android WebAuthn input validation flaw enables renderer-compromised sandbox escape via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome on ChromeOS Color heap buffer overflow enables sandbox escape via HTML, renderer compromise pre-151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome Print Preview validation flaw leaks cross-origin data via renderer compromise | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome ANGLE out-of-bounds read enables renderer sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Remote sandbox escape via crafted HTML in Chrome Android ANGLE pre-151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE bug enables post-renderer-compromise sandbox escape via crafted HTML in Chrome Android <151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE out-of-bounds write enables sandbox escape via crafted HTML in Chrome <151.0.7922.72 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Pre-151.0.7922.72 Chrome QUIC integer overflow enables sandbox escape from compromised renderer via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chromecast input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72) | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome ANGLE input validation bug allows sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in Chrome Views allows sandbox escape via crafted HTML from compromised renderer | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | iOS Chrome <151.0.7922.72 allows remote sandbox escape via crafted HTML page | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72 ANGLE uninitialized use leaks cross-origin data via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Remote cross-origin data leak via crafted HTML exploiting ANGLE uninitialized use in Chrome <151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Enterprise <151.0.7922.72 crypto bug allows discretionary access control bypass via network MITM | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | High-severity Chrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72 | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome Android GPU input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Insufficient input validation in Chrome Android Dawn allows remote sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 ADX decoder OOB on mid-stream channel layout change | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | High | FFmpeg RTP/ASF demuxer infinite loop DoS via undersized chunk in rtp_asf_fix_header | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | High | FFmpeg S/PDIF muxer out-of-bounds read via crafted DTS core_size during remuxing | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 NVDEC double-free causes memory corruption with crafted videos | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | High | FFmpeg 8.0–8.1.2 Vulkan HEVC decoder stack overflow via crafted bitstream enabling RCE | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | High | FFmpeg 2.1–8.1.2 VobSub demuxer heap overflow via excessive subtitle stream IDs (RCE) | Jul 29, 2026 | Aug 13, 2026 | Aug 4, 2026 | 6 days | |
| Fixed within SLA | High | IPv4 __ip_append_data paged allocation misaccounts fraggap causing undersized linear area, overstated pagedlen | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | High | IPv6 paged path fraggap misaccounting overflows skb via UDPv6 MSG_MORE/MSG_SPLICE_PAGES | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | High | af_unix race: unix_gc may run with gc_in_progress=false, breaking MSG_PEEK handling | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | High | KVM x86 UAF: role mismatch reuses shadow page after PDE split 2MB→4KB; rmap not removed | Jul 23, 2026 | Aug 7, 2026 | Aug 4, 2026 | 12 days | |
| Fixed within SLA | High | Heap overflow in BusyBox 1.38.0 shell/ash.c evalcommand() enables DoS via crafted input | Aug 4, 2026 | Aug 4, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Heap overflow in BusyBox 1.38.0 shell/ash.c ifsbreakup() enabling DoS via crafted input | Aug 4, 2026 | Aug 4, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | BusyBox 1.38.0 awk_sub() use-after-free in editors/awk.c enables DoS via crafted AWK script | Aug 4, 2026 | Aug 4, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Greybus raw cdev on close after bundle disconnect causes panic | Jul 20, 2026 | Aug 4, 2026 | Jul 30, 2026 | 10 days | |
| Fixed within SLA | High | Linux Greybus raw: use-after-free on write after disconnect triggers kernel panic | Jul 20, 2026 | Aug 4, 2026 | Jul 30, 2026 | 10 days | |
| Fixed within SLA | High | Linux ice driver double-free of skb during tx ring cleanup after TSO/CSUM failure | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | High | Netfilter nf_tables: netlink dump race from non-RCU hook list joins during commit | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | High | ceph: Missing folio_put for writeback-ineligible folios removed from batch causes reference leak | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.