Updated 04:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | High | libceph __ceph_x_decrypt out-of-bounds read when hdr->magic accessed without header-size check | Jul 16, 2026 | Jul 31, 2026 | Jul 30, 2026 | 14 days | |
| Fixed within SLA | Medium | KVM nSVM: Ignored CR3 load failure on nested #VMEXIT causes corrupted vCPU state | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 42 days | |
| Fixed within SLA | Medium | Deferred split queue race during folio migration marks dst partially mapped, triggers WARN | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 42 days | |
| Fixed within SLA | Medium | damos_walk vs kdamond_fn exit race leads unhandled requests and indefinite wait deadlock | Jun 19, 2026 | Aug 3, 2026 | Jul 30, 2026 | 42 days | |
| Fixed within SLA | Medium | Unloading snd_soc_nau8821 while jdet_work pending triggers kernel crash | Jun 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 43 days | |
| Fixed within SLA | Medium | Linux GFS2 gfs2_fill_super error-path memory leaks: kthreads and quota bitmap on RW transition | Jun 17, 2026 | Aug 1, 2026 | Jul 30, 2026 | 43 days |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.