Updated 21:00
Determinate Secure Packages distribution
secure-packages-rollingSupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.ContinuousCovered continuously, with no end date: as it follows Nixpkgs, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs as it moves. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
235
last 30 days
Fixed within SLA
24
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
262 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | High | HSR RCU readers race with RTM_DELLINK node frees, causing use-after-free | Aug 18, 2026 | Sep 2, 2026 | Aug 25, 2026 | 7 days | |
| Fixed within SLA | High | Chrome <151.0.7922.137 Blink use-after-free allows sandboxed remote code execution via crafted HTML | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.137 HTML use-after-free enables sandboxed RCE via crafted page | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed arbitrary code execution | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | High-severity TabStrip use-after-free enables sandbox escape via HTML on Chrome Mac <151.0.7922.137 | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome V8 pre-151.0.7922.137 allows sandboxed remote code execution | Aug 18, 2026 | Sep 2, 2026 | Aug 19, 2026 | 1 day | |
| Fixed within SLA | High | FFmpeg 7.0–8.1.2 vf_quirc heap OOB write via crafted PGS/SUP subtitles mismatched dimensions | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | Heap out-of-bounds write in FFmpeg PNG/APNG encoder eXIf handling (≤8.1.2) | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg <=8.1.2 MACE6 CAF bytes_per_packet integer overflow causes heap OOB write, RCE | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg up to 8.1.2 LCL/ZLIB decoder leaks uninitialized heap; short inflate enables ASLR bypass | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg ≤8.1.2 IAMF demuxer uncontrolled allocation from 17-byte input via count_label | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg ≤8.1.2 vf_hqdn3d heap OOB write when -reinit_filter 0 and resolution increases | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg 3.0-8.1.2 vf_swaprect OOB write on odd-width NV12 frames causing heap corruption | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg 3.4-8.1.2 vf_floodfill OOB write with -reinit_filter 0, heap corruption | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg <=8.1.2 heap corruption via TY demuxer OOB write using crafted ffconcat with -safe 0 | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | High | FFmpeg 2.7–8.1.2 TDSC decoder OOB write causing heap corruption and potential RCE | Aug 10, 2026 | Aug 25, 2026 | Aug 18, 2026 | 8 days | |
| Fixed within SLA | Low | Jun 15, 2026 | Sep 13, 2026 | Aug 18, 2026 | 63 days | ||
| Fixed within SLA | High | mlx5e XSK race: unlocked ICOSQ IRQ trigger during NAPI affinity change causes CQE errors | Aug 12, 2026 | Aug 27, 2026 | Aug 15, 2026 | 2 days | |
| Fixed within SLA | High | High severity use-after-free in Aura allows sandbox escape on Chrome Linux <151.0.7922.109 | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | High | Use-after-free in Chrome HTML before 151.0.7922.109 enables remote heap corruption | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | High | Use-after-free in Chrome Views pre-151.0.7922.109 allows remote heap corruption via crafted HTML | Aug 12, 2026 | Aug 27, 2026 | Aug 14, 2026 | 2 days | |
| Fixed within SLA | High | fbdev omap2 omapfb_mmap race with OMAPFB_SETUP_PLANE leads to use-after-free | Aug 4, 2026 | Aug 19, 2026 | Aug 12, 2026 | 8 days | |
| Fixed within SLA | Medium | Linux wifi ath11k: memory leaks in beacon template setup error paths (EMA/MBSSID) | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | Medium | Linux kernel: Deadlock deleting BPF local storage in NMI due to RCU deferral | Jul 27, 2026 | Sep 10, 2026 | Aug 12, 2026 | 16 days | |
| Fixed within SLA | Medium | Linux mt76 WiFi driver leaks skb on error path before mt76_mcu_skb_send_msg | Jul 23, 2026 | Sep 6, 2026 | Aug 12, 2026 | 20 days | |
| Fixed within SLA | Medium | f2fs data loss when fsync of new file races with checkpoint due to nat flags | Jul 20, 2026 | Sep 3, 2026 | Aug 12, 2026 | 23 days | |
| Fixed within SLA | Medium | Linux kernel af_alg AEAD AD length overflow when checking TX buffer size | Aug 10, 2026 | Sep 24, 2026 | Aug 12, 2026 | 2 days | |
| Fixed within SLA | Medium | drm/ttm: Infinite LRU loop on ttm_bo_swapout when swapout fails | Jul 16, 2026 | Aug 30, 2026 | Aug 12, 2026 | 27 days | |
| Fixed within SLA | Medium | Aug 11, 2026 | Sep 25, 2026 | Aug 12, 2026 | 1 day | ||
| Fixed within SLA | Medium | cJSON <=1.7.19 JSON Patch non-atomic; failed replace/move deletes target members | Aug 5, 2026 | Sep 19, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | cJSON <=1.7.19 cJSON_Compare exponential time on deep nested equal objects causes DoS | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | cJSON through 1.7.19: Untrusted RFC 6902 patch triggers recursion, stack exhaustion DoS | Aug 5, 2026 | Aug 20, 2026 | Aug 12, 2026 | 7 days | |
| Fixed within SLA | High | Aug 10, 2026 | Aug 25, 2026 | Aug 12, 2026 | 1 day | ||
| Fixed within SLA | High | Aug 10, 2026 | Aug 25, 2026 | Aug 12, 2026 | 1 day | ||
| Fixed within SLA | High | Google Chrome UI input validation flaw enables sandbox escape post-renderer compromise, pre-151.0.7922.109 | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Skia use-after-free in Chrome <151.0.7922.109 allows sandboxed RCE via crafted HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical | Use-after-free in Chrome Payments allows remote sandbox escape via crafted HTML (pre-151.0.7922.109) | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome V8 integer overflow allows sandbox RCE via crafted HTML pre-151.0.7922.109 | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Skia OOB write in Chrome <151.0.7922.109 enables sandbox escape via crafted HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Critical Chrome Views use-after-free enables sandbox escape via crafted HTML (pre-151.0.7922.109) | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical | Chrome Windows <151.0.7922.109 Media use-after-free enables remote sandbox escape via HTML | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical | Use-after-free in Chrome Android WebGL enables remote sandbox escape (pre-151.0.7922.109) | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Chrome <151.0.7922.109 Contextual Tasks input validation flaw allows remote privilege escalation via crafted HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | V8 vulnerability allows sandbox RCE via crafted HTML in Chrome <151.0.7922.109 | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Low | Chrome <151.0.7922.109 GPU integer overflow leaks cross-origin data; requires renderer compromise | Aug 10, 2026 | Nov 8, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical | Use-after-free in Chrome WebAuthn pre-151.0.7922.109 allows remote sandbox escape via HTML | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Use-after-free in Chrome Extensions allows sandboxed code execution via crafted extension pre-151.0.7922.109 | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | Critical | Insufficient input validation in Chrome Codecs pre-151.0.7922.109 allows remote sandbox escape via HTML | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Google Chrome Windows Media use-after-free enables sandbox escape via crafted HTML (pre-151.0.7922.109) | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day | |
| Fixed within SLA | High | Out-of-bounds write in Chrome V8 pre-151.0.7922.109 allows sandbox RCE via HTML | Aug 10, 2026 | Aug 25, 2026 | Aug 11, 2026 | 1 day |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.