Skip to content
All distributions

Updated 20:01

Determinate Secure Packages distribution

secure-packages-rollingSupportedFIPS supportedContinuous

Built on Nixpkgs as it moves. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

235

last 30 days

Fixed within SLA

24

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

262 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
OpenHighSQL injection in PostgreSQL EXTRACT() deparse allows superuser execution via hostile object definitionsAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL 18<18.5 pg_restore_attribute_stats type confusion allows RCE as database OS userAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory-derived values via non-ctid inputAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL logical decoding auth flaw lets REPLICATION users execute arbitrary code as server OS accountAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL 'internal' type confusion lets any user execute arbitrary code; affects <18.5,17.11,16.15,15.19,14.24Aug 24, 2026Sep 8, 2026
OpenHighType confusion in PostgreSQL portal/cursor lifecycle enables OS-level code execution; pre-18.5, 17.11, 16.15, 15.19, 14.24Aug 24, 2026Sep 8, 2026
OpenHighPostgreSQL 32-bit pltcl/plperl integer wraparound causes undersized allocation, OOB write, RCEAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL plperl tied-hash return heap overflow enables RCE as database OS userAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL tsvector/tsquery integer wraparound allows OOB write, potential RCE by unprivileged usersAug 24, 2026Sep 8, 2026
OpenHighHeap buffer overflow in PostgreSQL to_char(timestamptz) via long timezone abbreviation enables RCEAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL refint type confusion allows arbitrary OS code execution; no CVE; affects pre-18.5/17.11/16.15/15.19/14.24Aug 24, 2026Sep 8, 2026
OpenHighPostgreSQL pg_dump heap buffer overflow in transform lists enables RCE; versions <18.5/17.11/16.15/15.19/14.24Aug 24, 2026Sep 8, 2026
OpenHighpsql COPY FROM STDIN pre-input error executes data lines as commandsAug 24, 2026Sep 8, 2026
OpenHighInteger wraparound RCE in PostgreSQL fuzzystrmatch via levenshtein/less_equal before 18.5/17.11/16.15/15.19/14.24Aug 24, 2026Sep 8, 2026
OpenHighPostgreSQL stack buffer overflow in OUT parameter name matching with limited 0/1-byte writesAug 24, 2026Sep 8, 2026
OpenHighPostgreSQL regexp heap overflow enables arbitrary code execution via invalid encoding input affects pre-18.5/17.11/16.15/15.19/14.24Aug 24, 2026Sep 8, 2026
OpenHighpg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict; affects pre-18.5/17.11/16.15/15.19/14.24Aug 24, 2026Sep 8, 2026
OpenMediumPostgreSQL: Stale RLS from role/ownership changes enables unauthorized reads/writes via plan reuseAug 24, 2026Oct 8, 2026
OpenMediumPostgreSQL pgcrypto disabled-cipher bug allows cleartext recovery; wrong-key decrypt bypasses MDCAug 24, 2026Oct 8, 2026
OpenMediumPostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24Aug 24, 2026Oct 8, 2026
OpenMediumPostgreSQL pg_trgm picksplit buffer over-read leaks memory via split choices; pre-18.5/17.11/16.15/15.19/14.24Aug 24, 2026Oct 8, 2026
OpenMediumAttacker-controlled CR in configparser multiline values injects unexpected configuration keys and valuesAug 24, 2026Oct 8, 2026
OpenMediumPrivilege check bypass in PostgreSQL DDL enables DoS via type dependencies (pre-18.5/17.11/16.15/15.19/14.24)Aug 24, 2026Oct 8, 2026
OpenMediumPostgreSQL 16–18 SCRAM iteration-count leak allows unauthenticated user enumeration when non-default scram_iterationsAug 24, 2026Oct 8, 2026
OpenLowPostgreSQL ECPG integer underflow enables DoS via bytea without prefix; client memory overwriteAug 24, 2026Nov 22, 2026
OpenLowPostgreSQL ALTER TABLE ALTER TYPE misassigns stats ownership, enabling unauthorized DROP/ALTER STATISTICSAug 24, 2026Nov 22, 2026
OpenLowPostgreSQL amcheck EXECUTE privilege allows arbitrary function execution as expression index ownersAug 24, 2026Nov 22, 2026
Fixed within SLAHighUse-after-free from skb->cb reuse in mac80211 mesh fast-RX rate handlingAug 24, 2026Sep 8, 2026Aug 27, 20263 days
Fixed within SLAMediumNULL pointer dereference when reading crafted HDF5 attribute with invalid variable-length datatypeAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAMediumDouble free vulnerability in HDF5 h5repack triggered by crafted file oversized chunk sizeAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAMediumHeap overflow in HDF5 SOHM list-index deserialization triggers DoS with crafted file through 2.1.1Aug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAHighV8 type confusion enables remote code execution within Chrome sandbox pre-151.0.7922.169Aug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighANGLE buffer overflow in Chrome Android <151.0.7922.169 enables sandbox escape remote code executionAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighWebGL use-after-free in Chrome <151.0.7922.169 enables sandbox RCE via crafted HTMLAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighChrome <151.0.7922.169 USB race enables code execution outside sandbox via crafted HTMLAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighV8 miscalculation enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.169Aug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLALowChrome pre-151.0.7922.169 GPU uninitialized resource leaks memory outside sandbox via crafted HTMLAug 24, 2026Nov 22, 2026Aug 25, 20261 day
Fixed within SLAMediumHigh-severity Skia info leak in Chrome <151.0.7922.169 enables origin policy bypass via crafted HTML pageAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAHighChrome Mac <151.0.7922.169 Browser use-after-free enables remote sandbox-escape RCE via crafted HTMLAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAMediumChrome Android Core reference resolution bug leaks sensitive data via crafted HTML pre-151.0.7922.169Aug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAHighGoogle Chrome <151.0.7922.169 V8 type confusion allows sandboxed RCE via crafted HTMLAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAHighChrome CredentialProvider link-following on Windows allows local sandbox escape pre-151.0.7922.169Aug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLACriticalCritical Dawn buffer overflow allows remote code execution outside sandbox on Android Chrome <151.0.7922.169Aug 24, 2026Aug 31, 2026Aug 25, 20261 day
Fixed within SLAHighBuffer overflow in Chrome WebGL before 151.0.7922.169 enables RCE outside sandbox via crafted HTML page.Aug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAMediumChrome <151.0.7922.169 CORS flaw enables compromised renderer to bypass site isolation via crafted HTMLAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAHighKVM guest_memfd memslot offset+size signed overflow bypasses i_size bound checkAug 18, 2026Sep 2, 2026Aug 25, 20267 days
Fixed within SLACriticalLinux kernel netfs potential tearing and i_size_seqcount corruption updating remote_i_size/zero_point without i_lockAug 18, 2026Aug 25, 2026Aug 25, 20266 days
Fixed within SLAMediumNetfs zero_point misupdated with i_size > remote_i_size, causing short reads on EOFAug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAMediumdrm/msm/adreno: missing of_node_put causes node reference leak in a6xx_gpu_init()Aug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAMediumEROFS xattr inode init leaks folio reference when metabuf not dropped on errorsAug 18, 2026Oct 2, 2026Aug 25, 20266 days

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems