Updated 23:01
Determinate Secure Packages distribution
secure-packages-26.05SupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.Until November 2029Covered until November 2029. Until then, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
479
last 30 days
Fixed within SLA
18
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
506 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 Presentation policy flaw enables remote navigation bypass via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Google Chrome pre-151 Extensions UI security flaw enables malicious extension-based UI spoofing | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Blink same-origin policy bypass in Chrome before 151.0.7922.72 via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Chrome Network input validation flaw enables sandbox escape from compromised renderer via HTML | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Medium | Site Isolation bypass in Chrome <151.0.7922.72 via crafted HTML after renderer compromise | Aug 7, 2026 | Sep 21, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | High severity V8 use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Chrome <151.0.7922.72 Navigation use-after-free enables sandbox escape via crafted HTML | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Critical Chrome Ozone use-after-free enables remote sandbox escape via crafted HTML before 151.0.7922.72 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Critical ANGLE input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72) | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Race in macOS Chrome Updater allows local privilege escalation before 151.0.7922.72 via malicious file | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Skia use-after-free enables sandbox escape via crafted HTML in Chrome <151.0.7922.72 | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Use-after-free in Views enables sandbox escape on Chrome before 151.0.7922.72 via crafted HTML | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Use-after-free in Chrome Compositing allows sandbox escape from compromised renderer via HTML (pre-151.0.7922.72) | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Medium | ublk I/O cancellation may never complete due to stale per-IO canceled flag after partial fetch | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Medium | PowerPC64: PMD migration/munmap race causes VM_BUG_ON in pmdp_huge_get_and_clear_full | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | High | Use-after-free when filling offloaded BPF map/prog info due to netns teardown race | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Medium | Linux kernel ice driver TX timestamp ring cleanup race causes NULL dereference | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Medium | Potential NULL dereference in ice_set_ringparam error path due to uncleared ICE_TX_RING_FLAGS_TXTIME | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | High | GSO headers not pulled in qdisc_pkt_len_segs_init risk TSO memcpy crash, security issue | Jul 27, 2026 | Aug 11, 2026 | Aug 7, 2026 | 11 days | |
| Fixed within SLA | High | BPF verifier omits ld_{abs,ind} failure path analysis in BTF subprograms | Jul 27, 2026 | Aug 11, 2026 | Aug 7, 2026 | 11 days | |
| Fixed within SLA | High | BPF sock_ops GET_SK/GET_FIELD miss zeroing when dst==src, causing OOB read and leak | Jul 23, 2026 | Aug 7, 2026 | Aug 7, 2026 | 15 days | |
| Fixed within SLA | Medium | ntfs3 attr_data_get_block_locked() misses vcn0 run load across segments, triggers WARN_ON | Jul 20, 2026 | Sep 3, 2026 | Aug 7, 2026 | 18 days | |
| Fixed within SLA | High | SOCKMAP hides inflight fds from AF_UNIX GC causing leaks, UAF, and incorrect SCM counts | Aug 4, 2026 | Aug 19, 2026 | Aug 7, 2026 | 3 days | |
| Fixed within SLA | Medium | Linux kernel drm/ttm ttm_bo_shrink() infinite LRU walk on backup failure | Jul 16, 2026 | Aug 30, 2026 | Aug 7, 2026 | 22 days | |
| Fixed within SLA | Medium | rtw88 8821CE probe crash due to NULL pci_upstream_bridge on root bus | Jun 28, 2026 | Aug 12, 2026 | Aug 7, 2026 | 40 days | |
| Fixed within SLA | Medium | nf_tables reset commit_mutex causes circular lock dependency with nft reset, ipset list, iptables-nft -m set | Jun 28, 2026 | Aug 12, 2026 | Aug 7, 2026 | 40 days | |
| Fixed within SLA | Medium | Concurrent nft_counter dump-and-reset race can double-subtract, underrunning netfilter counter totals | Aug 7, 2026 | Sep 21, 2026 | Aug 7, 2026 | same day | |
| Fixed within SLA | High | Chromoting on Linux before 151.0.7922.72 enables OS-level privilege escalation via malicious network traffic | Aug 4, 2026 | Aug 19, 2026 | Aug 5, 2026 | 1 day | |
| Fixed within SLA | Critical | glibc scanf %mc width >1024 triggers 1-byte heap overflow in v2.7-2.43 | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Side-channel leak in Chrome Media exposes cross-origin data via crafted HTML (pre-151.0.7922.72) | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72 Dawn use-after-free enables sandboxed RCE via crafted HTML, low severity | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72: Insufficient policy enforcement allows remote UI spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient input validation in Chrome DevTools pre-151.0.7922.72 allows navigation bypass via malicious file | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome for iOS prior to 151.0.7922.72 UI spoofing via crafted HTML page | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | High | Chrome <151.0.7922.72: PDFium use-after-free enables sandboxed code execution via crafted PDF | Aug 4, 2026 | Aug 19, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome for iOS <151.0.7922.72 exposes process memory to local physical attacker | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Passwords pre-151.0.7922.72 enables remote UI spoofing via malicious network traffic | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Passwords pre-151.0.7922.72 untrusted input validation flaw enables remote UI spoofing via malicious network traffic | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome Settings bug before 151.0.7922.72 allowed remote UI spoofing via malicious traffic | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Input implementation flaw in Chrome Android <151.0.7922.72 enables remote UI spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Lens in Chrome <151.0.7922.72 enables UI spoofing via crafted HTML after renderer compromise | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Google Chrome WebXR info disclosure from process memory via crafted HTML pre-151.0.7922.72 | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Insufficient Speech API policy in Chrome <151.0.7922.72 enables compromised renderer cross-origin data leak | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | UI spoofing vulnerability in Chrome iOS <151.0.7922.72 via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Critical | Chrome Google Lens insufficient input validation allows renderer sandbox escape via crafted HTML | Aug 4, 2026 | Aug 11, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Pre-151.0.7922.72 Chrome WebGL bug exposes process memory via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Android USB policy flaw prior to 151.0.7922.72 leaks cross-origin data via compromised renderer | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome Android pre-151.0.7922.72 PIP race enables remote domain spoofing via crafted HTML | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Medium | Chrome <151.0.7922.72: Incorrect Extensions security UI enables malicious extension UI spoofing | Aug 4, 2026 | Sep 18, 2026 | Aug 4, 2026 | same day | |
| Fixed within SLA | Low | Chrome Passwords <151.0.7922.72 cross-origin data leak via renderer-compromised crafted HTML | Aug 4, 2026 | Nov 2, 2026 | Aug 4, 2026 | same day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.