Skip to content
All distributions

Updated 23:01

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

479

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

506 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAMediumChrome pre-151.0.7922.72 Presentation policy flaw enables remote navigation bypass via crafted HTMLAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumGoogle Chrome pre-151 Extensions UI security flaw enables malicious extension-based UI spoofingAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumBlink same-origin policy bypass in Chrome before 151.0.7922.72 via crafted HTMLAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAHighChrome Network input validation flaw enables sandbox escape from compromised renderer via HTMLAug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAMediumSite Isolation bypass in Chrome <151.0.7922.72 via crafted HTML after renderer compromiseAug 7, 2026Sep 21, 2026Aug 11, 20264 days
Fixed within SLAHighHigh severity V8 use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72Aug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAHighChrome <151.0.7922.72 Navigation use-after-free enables sandbox escape via crafted HTMLAug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLACriticalCritical Chrome Ozone use-after-free enables remote sandbox escape via crafted HTML before 151.0.7922.72Aug 7, 2026Aug 14, 2026Aug 11, 20264 days
Fixed within SLACriticalCritical ANGLE input validation flaw enables sandbox escape via crafted HTML (Chrome <151.0.7922.72)Aug 7, 2026Aug 14, 2026Aug 11, 20264 days
Fixed within SLAHighRace in macOS Chrome Updater allows local privilege escalation before 151.0.7922.72 via malicious fileAug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAHighSkia use-after-free enables sandbox escape via crafted HTML in Chrome <151.0.7922.72Aug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLACriticalUse-after-free in Views enables sandbox escape on Chrome before 151.0.7922.72 via crafted HTMLAug 7, 2026Aug 14, 2026Aug 11, 20264 days
Fixed within SLAHighUse-after-free in Chrome Compositing allows sandbox escape from compromised renderer via HTML (pre-151.0.7922.72)Aug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAMediumublk I/O cancellation may never complete due to stale per-IO canceled flag after partial fetchJul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLAMediumPowerPC64: PMD migration/munmap race causes VM_BUG_ON in pmdp_huge_get_and_clear_fullJul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLAHighUse-after-free when filling offloaded BPF map/prog info due to netns teardown raceJul 27, 2026Aug 11, 2026Aug 11, 202615 days
Fixed within SLAMediumLinux kernel ice driver TX timestamp ring cleanup race causes NULL dereferenceJul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLAMediumPotential NULL dereference in ice_set_ringparam error path due to uncleared ICE_TX_RING_FLAGS_TXTIMEJul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLAHighGSO headers not pulled in qdisc_pkt_len_segs_init risk TSO memcpy crash, security issueJul 27, 2026Aug 11, 2026Aug 7, 202611 days
Fixed within SLAHighBPF verifier omits ld_{abs,ind} failure path analysis in BTF subprogramsJul 27, 2026Aug 11, 2026Aug 7, 202611 days
Fixed within SLAHighBPF sock_ops GET_SK/GET_FIELD miss zeroing when dst==src, causing OOB read and leakJul 23, 2026Aug 7, 2026Aug 7, 202615 days
Fixed within SLAMediumntfs3 attr_data_get_block_locked() misses vcn0 run load across segments, triggers WARN_ONJul 20, 2026Sep 3, 2026Aug 7, 202618 days
Fixed within SLAHighSOCKMAP hides inflight fds from AF_UNIX GC causing leaks, UAF, and incorrect SCM countsAug 4, 2026Aug 19, 2026Aug 7, 20263 days
Fixed within SLAMediumLinux kernel drm/ttm ttm_bo_shrink() infinite LRU walk on backup failureJul 16, 2026Aug 30, 2026Aug 7, 202622 days
Fixed within SLAMediumrtw88 8821CE probe crash due to NULL pci_upstream_bridge on root busJun 28, 2026Aug 12, 2026Aug 7, 202640 days
Fixed within SLAMediumnf_tables reset commit_mutex causes circular lock dependency with nft reset, ipset list, iptables-nft -m setJun 28, 2026Aug 12, 2026Aug 7, 202640 days
Fixed within SLAMediumConcurrent nft_counter dump-and-reset race can double-subtract, underrunning netfilter counter totalsAug 7, 2026Sep 21, 2026Aug 7, 2026same day
Fixed within SLAHighChromoting on Linux before 151.0.7922.72 enables OS-level privilege escalation via malicious network trafficAug 4, 2026Aug 19, 2026Aug 5, 20261 day
Fixed within SLACriticalglibc scanf %mc width >1024 triggers 1-byte heap overflow in v2.7-2.43Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumSide-channel leak in Chrome Media exposes cross-origin data via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome <151.0.7922.72 Dawn use-after-free enables sandboxed RCE via crafted HTML, low severityAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS <151.0.7922.72: Insufficient policy enforcement allows remote UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient input validation in Chrome DevTools pre-151.0.7922.72 allows navigation bypass via malicious fileAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome for iOS prior to 151.0.7922.72 UI spoofing via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome <151.0.7922.72: PDFium use-after-free enables sandboxed code execution via crafted PDFAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLALowChrome for iOS <151.0.7922.72 exposes process memory to local physical attackerAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Passwords pre-151.0.7922.72 enables remote UI spoofing via malicious network trafficAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Passwords pre-151.0.7922.72 untrusted input validation flaw enables remote UI spoofing via malicious network trafficAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome Settings bug before 151.0.7922.72 allowed remote UI spoofing via malicious trafficAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInput implementation flaw in Chrome Android <151.0.7922.72 enables remote UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Lens in Chrome <151.0.7922.72 enables UI spoofing via crafted HTML after renderer compromiseAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome WebXR info disclosure from process memory via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient Speech API policy in Chrome <151.0.7922.72 enables compromised renderer cross-origin data leakAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumUI spoofing vulnerability in Chrome iOS <151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Google Lens insufficient input validation allows renderer sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome WebGL bug exposes process memory via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowChrome Android USB policy flaw prior to 151.0.7922.72 leaks cross-origin data via compromised rendererAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android pre-151.0.7922.72 PIP race enables remote domain spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72: Incorrect Extensions security UI enables malicious extension UI spoofingAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowChrome Passwords <151.0.7922.72 cross-origin data leak via renderer-compromised crafted HTMLAug 4, 2026Nov 2, 2026Aug 4, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems