Skip to content
All distributions

Updated 21:00

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

503

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

530 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAHighHSR RTM_DELLINK frees nodes without RCU, causing generic-netlink reader use-after-freeAug 19, 2026Sep 3, 2026Aug 19, 2026same day
Fixed within SLAHighmlx5e XSK: Unprotected ICOSQ IRQ trigger races with NAPI and CPU affinity changesAug 12, 2026Aug 27, 2026Aug 15, 20262 days
Fixed within SLAHighFFmpeg 7.0–8.1.2 vf_quirc heap OOB write via mismatched PGS/SUP frame dimensionsAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighHeap OOB write in FFmpeg PNG/APNG encoders <=8.1.2 via malicious eXIf chunk, RCEAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg ≤8.1.2 MACE6 signed integer overflow leads to heap OOB write via CAFAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg <=8.1.2 LCL/ZLIB decoder info leak via short zlib decompressionAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg ≤8.1.2 IAMF demuxer OOM via crafted count_label during format probingAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg <=8.1.2 vf_hqdn3d heap out-of-bounds write with -reinit_filter 0 and growing framesAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg 3.0–8.1.2 vf_swaprect OOB write on NV12 odd-width frames causes heap corruptionAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg 3.4-8.1.2 vf_floodfill OOB write on dynamic frames with -reinit_filter 0Aug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg <=8.1.2 OOB write via crafted ffconcat (-safe 0) in TY demuxerAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighFFmpeg 2.7–8.1.2 TDSC decoder OOB write on frame dimension changes enables RCEAug 11, 2026Aug 26, 2026Aug 15, 20263 days
Fixed within SLAHighAura use-after-free in Chrome Linux pre-151.0.7922.109 enables sandbox escape via HTML from compromised rendererAug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAHighUse-after-free in Chrome HTML enables remote heap corruption before 151.0.7922.109Aug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAHighChrome Views use-after-free before 151.0.7922.109 allows heap corruption via crafted HTML and gesturesAug 12, 2026Aug 27, 2026Aug 14, 20262 days
Fixed within SLAHighfbdev omap2: omapfb_mmap race with OMAPFB_SETUP_PLANE causes use-after-freeAug 4, 2026Aug 19, 2026Aug 12, 20268 days
Fixed within SLAMediumath11k: memory leaks in beacon template setup error paths (EMA/MBSSID)Jul 27, 2026Sep 10, 2026Aug 12, 202616 days
Fixed within SLAMediumBPF local storage deletion in NMI or reentrant contexts may deadlock via RCU freeingJul 27, 2026Sep 10, 2026Aug 12, 202616 days
Fixed within SLAMediummt76 wifi driver memory leak on sta_wed_update/sta_key_tlv failures after skb allocationJul 23, 2026Sep 6, 2026Aug 12, 202620 days
Fixed within SLAMediumLinux f2fs data loss when new-file fsync races with checkpoint nat_entry flagsJul 20, 2026Sep 3, 2026Aug 12, 202623 days
Fixed within SLAMediumLinux kernel af_alg AEAD AD length arithmetic overflow during TX buffer size checkAug 4, 2026Sep 18, 2026Aug 12, 20268 days
Fixed within SLAMediumdrm/ttm: Infinite LRU walk restoring bulk_move after ttm_bo_swapout() swapout failureJul 16, 2026Aug 30, 2026Aug 12, 202627 days
Fixed within SLAMediumio_uring zcrx post-open error handling prematurely frees ctx; page pools may persistAug 11, 2026Sep 25, 2026Aug 12, 20261 day
Fixed within SLAMediumcJSON ≤1.7.19 JSON Patch non-atomic; failed replace/move deletes target membersAug 5, 2026Sep 19, 2026Aug 12, 20267 days
Fixed within SLAHighcJSON 1.7.19 and earlier: cJSON_Compare exponential complexity allows DoS via nested JSONAug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAHighcJSON <=1.7.19: Untrusted JSON Patch via cJSONUtils_ApplyPatches triggers uncontrolled recursion and stack exhaustion DoSAug 5, 2026Aug 20, 2026Aug 12, 20267 days
Fixed within SLAHighglibc ≤ 2.43 ungetwc wrong buffer causes under-read with overlapping encodings, data leak/crashAug 4, 2026Aug 19, 2026Aug 12, 20267 days
Fixed within SLAHighglibc <=2.43 iconv assertion failure on IBM1390/IBM1399 may allow remote crashAug 4, 2026Aug 19, 2026Aug 12, 20267 days
Fixed within SLAHighChrome UI input validation flaw enables sandbox escape from renderer via crafted HTML pre-151.0.7922.109Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAHighSkia use-after-free in Chrome <151.0.7922.109 enables sandboxed RCE via crafted HTMLAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLACriticalUse-after-free in Chrome Payments allows remote sandbox escape via crafted HTML pre-151.0.7922.109Aug 11, 2026Aug 18, 2026Aug 11, 2026same day
Fixed within SLAHighV8 integer overflow enables sandboxed arbitrary code execution in Chrome <151.0.7922.109 via crafted HTMLAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAHighSkia out-of-bounds write enables sandbox escape from compromised renderer in Chrome <151.0.7922.109Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAHighUse-after-free in Chrome Views enables sandbox escape from compromised renderer via crafted HTMLAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLACriticalUse-after-free in Chrome Media on Windows pre-151.0.7922.109 enables remote sandbox escape via crafted HTMLAug 11, 2026Aug 18, 2026Aug 11, 2026same day
Fixed within SLACriticalCritical WebGL use-after-free allows remote sandbox escape in Android Chrome <151.0.7922.109Aug 11, 2026Aug 18, 2026Aug 11, 2026same day
Fixed within SLAHighChrome pre-151.0.7922.109 Contextual Tasks input validation flaw allows remote privilege escalation via crafted HTMLAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAHighChrome V8 sandbox arbitrary code execution via crafted HTML pre-151.0.7922.109Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLALowChrome GPU integer overflow allowed cross-origin data leak via crafted page (pre-151.0.7922.109)Aug 11, 2026Nov 9, 2026Aug 11, 2026same day
Fixed within SLACriticalGoogle Chrome WebAuthn use-after-free allows remote sandbox escape via crafted HTML (pre-151.0.7922.109)Aug 11, 2026Aug 18, 2026Aug 11, 2026same day
Fixed within SLAHighUse-after-free in Chrome Extensions pre-151.0.7922.109 enables sandboxed arbitrary code executionAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLACriticalInsufficient Chrome Codecs input validation enables remote sandbox escape via crafted HTML (pre-151.0.7922.109)Aug 11, 2026Aug 18, 2026Aug 11, 2026same day
Fixed within SLAHighChrome Windows pre-151.0.7922.109 Media use-after-free enables sandbox escape via crafted HTMLAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAHighChrome V8 out-of-bounds write before 151.0.7922.109 enables sandboxed RCE via crafted HTMLAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLALowSkia uninitialized use in Chrome <151.0.7922.109 enables cross-origin data leak after renderer compromiseAug 11, 2026Nov 9, 2026Aug 11, 2026same day
Fixed within SLALowUninitialized use in Skia allows cross-origin data leak in Chrome before 151.0.7922.109 after renderer compromiseAug 11, 2026Nov 9, 2026Aug 11, 2026same day
Fixed within SLAHighChrome Views use-after-free enables remote heap corruption via crafted HTML requiring user gestures before 151.0.7922.109Aug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLAHighChrome Views use-after-free on Windows <151.0.7922.109 allows heap corruption via HTML and UI gesturesAug 11, 2026Aug 26, 2026Aug 11, 2026same day
Fixed within SLACriticalANGLE out-of-bounds write in Chrome Android pre-151.0.7922.109 enables remote sandbox escapeAug 11, 2026Aug 18, 2026Aug 11, 2026same day
Fixed within SLAHighChrome Base heap buffer overflow pre-151.0.7922.109 via crafted malicious extensionAug 11, 2026Aug 26, 2026Aug 11, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems