Updated 21:00
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
503
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
530 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | High | HSR RTM_DELLINK frees nodes without RCU, causing generic-netlink reader use-after-free | Aug 19, 2026 | Sep 3, 2026 | Aug 19, 2026 | same day | |
| Fixed within SLA | High | mlx5e XSK: Unprotected ICOSQ IRQ trigger races with NAPI and CPU affinity changes | Aug 12, 2026 | Aug 27, 2026 | Aug 15, 2026 | 2 days | |
| Fixed within SLA | High | FFmpeg 7.0–8.1.2 vf_quirc heap OOB write via mismatched PGS/SUP frame dimensions | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | Heap OOB write in FFmpeg PNG/APNG encoders <=8.1.2 via malicious eXIf chunk, RCE | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg ≤8.1.2 MACE6 signed integer overflow leads to heap OOB write via CAF | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg <=8.1.2 LCL/ZLIB decoder info leak via short zlib decompression | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label during format probing | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg <=8.1.2 vf_hqdn3d heap out-of-bounds write with -reinit_filter 0 and growing frames | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg 3.0–8.1.2 vf_swaprect OOB write on NV12 odd-width frames causes heap corruption | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg 3.4-8.1.2 vf_floodfill OOB write on dynamic frames with -reinit_filter 0 | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg <=8.1.2 OOB write via crafted ffconcat (-safe 0) in TY demuxer | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | FFmpeg 2.7–8.1.2 TDSC decoder OOB write on frame dimension changes enables RCE | Aug 11, 2026 | Aug 26, 2026 | Aug 15, 2026 | 3 days | |
| Fixed within SLA | High | Aura use-after-free in Chrome Linux pre-151.0.7922.109 enables sandbox escape via HTML from compromised renderer | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | High | Use-after-free in Chrome HTML enables remote heap corruption before 151.0.7922.109 | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | High | Chrome Views use-after-free before 151.0.7922.109 allows heap corruption via crafted HTML and gestures | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | High | fbdev omap2: omapfb_mmap race with OMAPFB_SETUP_PLANE causes use-after-free | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | Medium | ath11k: memory leaks in beacon template setup error paths (EMA/MBSSID) | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | Medium | BPF local storage deletion in NMI or reentrant contexts may deadlock via RCU freeing | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | Medium | mt76 wifi driver memory leak on sta_wed_update/sta_key_tlv failures after skb allocation | Jul 23, 2026 | Sep 6, 2026 | Aug 12, 2026 | 20 days | |
| Fixed within SLA | Medium | Linux f2fs data loss when new-file fsync races with checkpoint nat_entry flags | Jul 20, 2026 | Sep 3, 2026 | Aug 12, 2026 | 23 days | |
| Fixed within SLA | Medium | Linux kernel af_alg AEAD AD length arithmetic overflow during TX buffer size check | Aug 4, 2026 | Sep 18, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | Medium | drm/ttm: Infinite LRU walk restoring bulk_move after ttm_bo_swapout() swapout failure | Jul 16, 2026 | Aug 30, 2026 | Aug 12, 2026 | 27 days | |
| Fixed within SLA | Medium | io_uring zcrx post-open error handling prematurely frees ctx; page pools may persist | Aug 11, 2026 | Sep 25, 2026 | Aug 12, 2026 | 1 day | |
| Fixed within SLA | Medium | cJSON ≤1.7.19 JSON Patch non-atomic; failed replace/move deletes target members | Aug 5, 2026 | Sep 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | cJSON 1.7.19 and earlier: cJSON_Compare exponential complexity allows DoS via nested JSON | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | cJSON <=1.7.19: Untrusted JSON Patch via cJSONUtils_ApplyPatches triggers uncontrolled recursion and stack exhaustion DoS | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | glibc ≤ 2.43 ungetwc wrong buffer causes under-read with overlapping encodings, data leak/crash | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | glibc <=2.43 iconv assertion failure on IBM1390/IBM1399 may allow remote crash | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | Chrome UI input validation flaw enables sandbox escape from renderer via crafted HTML pre-151.0.7922.109 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Skia use-after-free in Chrome <151.0.7922.109 enables sandboxed RCE via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in Chrome Payments allows remote sandbox escape via crafted HTML pre-151.0.7922.109 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | V8 integer overflow enables sandboxed arbitrary code execution in Chrome <151.0.7922.109 via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Skia out-of-bounds write enables sandbox escape from compromised renderer in Chrome <151.0.7922.109 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Views enables sandbox escape from compromised renderer via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical | Use-after-free in Chrome Media on Windows pre-151.0.7922.109 enables remote sandbox escape via crafted HTML | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical | Critical WebGL use-after-free allows remote sandbox escape in Android Chrome <151.0.7922.109 | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome pre-151.0.7922.109 Contextual Tasks input validation flaw allows remote privilege escalation via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 sandbox arbitrary code execution via crafted HTML pre-151.0.7922.109 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Low | Chrome GPU integer overflow allowed cross-origin data leak via crafted page (pre-151.0.7922.109) | Aug 11, 2026 | Nov 9, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical | Google Chrome WebAuthn use-after-free allows remote sandbox escape via crafted HTML (pre-151.0.7922.109) | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions pre-151.0.7922.109 enables sandboxed arbitrary code execution | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical | Insufficient Chrome Codecs input validation enables remote sandbox escape via crafted HTML (pre-151.0.7922.109) | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome Windows pre-151.0.7922.109 Media use-after-free enables sandbox escape via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome V8 out-of-bounds write before 151.0.7922.109 enables sandboxed RCE via crafted HTML | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Low | Skia uninitialized use in Chrome <151.0.7922.109 enables cross-origin data leak after renderer compromise | Aug 11, 2026 | Nov 9, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Low | Uninitialized use in Skia allows cross-origin data leak in Chrome before 151.0.7922.109 after renderer compromise | Aug 11, 2026 | Nov 9, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome Views use-after-free enables remote heap corruption via crafted HTML requiring user gestures before 151.0.7922.109 | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome Views use-after-free on Windows <151.0.7922.109 allows heap corruption via HTML and UI gestures | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | Critical | ANGLE out-of-bounds write in Chrome Android pre-151.0.7922.109 enables remote sandbox escape | Aug 11, 2026 | Aug 18, 2026 | Aug 11, 2026 | same day | |
| Fixed within SLA | High | Chrome Base heap buffer overflow pre-151.0.7922.109 via crafted malicious extension | Aug 11, 2026 | Aug 26, 2026 | Aug 11, 2026 | same day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.