Skip to content
All distributions

Updated 23:01

Determinate Secure Packages distribution

secure-packages-rollingSupportedFIPS supportedContinuous

Built on Nixpkgs as it moves. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

210

last 30 days

Fixed within SLA

24

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

237 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLACriticalChrome <151.0.7922.72 WebSocket input validation bug enables sandbox escape from compromised rendererAug 5, 2026Aug 12, 2026Aug 11, 20266 days
Fixed within SLAMediumAndroid Chrome WebView <151.0.7922.72: insufficient input validation enables cross-origin data leakAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumFedCM in Chrome <151.0.7922.72 allows remote same-origin policy bypass via crafted HTMLAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumiOS Chrome pre-151.0.7922.72 cross-origin data leak via crafted HTMLAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumChrome iOS <151.0.7922.72: Insufficient input validation enables UXSS script/HTML injection via malicious trafficAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumChrome before 151.0.7922.72 Presentation policy flaw allowed remote navigation bypass via crafted HTMLAug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumChrome Extensions security UI bug allowed spoofing via malicious extension before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAMediumBlink same-origin policy bypass via crafted HTML in Chrome before 151.0.7922.72Aug 5, 2026Sep 19, 2026Aug 11, 20266 days
Fixed within SLAHighInsufficient input validation in Chrome Network enables sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAMediumChrome pre-151.0.7922.72 SiteIsolation flaw allows compromised renderer to bypass isolation via crafted HTMLAug 7, 2026Sep 21, 2026Aug 11, 20264 days
Fixed within SLAHighV8 use-after-free in Chrome <151.0.7922.72 allows sandboxed remote code execution via crafted HTML pageAug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAHighChrome Navigation use-after-free allowed sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLACriticalCritical use-after-free in Chrome Ozone pre-151.0.7922.72 enables remote crafted-HTML sandbox escapeAug 7, 2026Aug 14, 2026Aug 11, 20264 days
Fixed within SLACriticalCritical ANGLE input validation flaw enables remote sandbox escape via crafted HTML in Chrome <151.0.7922.72Aug 7, 2026Aug 14, 2026Aug 11, 20264 days
Fixed within SLAHighCritical race in Chrome Updater on Mac pre-151.0.7922.72 enables local privilege escalationAug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAHighCritical Skia use-after-free in Google Chrome <151.0.7922.72 enables sandbox escape via crafted HTMLAug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLACriticalChrome <151.0.7922.72: Views use-after-free enables sandbox escape via crafted HTMLAug 7, 2026Aug 14, 2026Aug 11, 20264 days
Fixed within SLAHighChrome Compositing use-after-free pre-151.0.7922.72 enables sandbox escape via crafted HTMLAug 7, 2026Aug 22, 2026Aug 11, 20264 days
Fixed within SLAHighFFmpeg ADX decoder OOB read/write on mid-stream extradata channel change (v4.4–8.1.2)Jul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAHighFFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS in rtp_asf_fix_headerJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAHighFFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_sizeJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAHighFFmpeg 4.4–8.1.2 NVDEC double-free enables memory corruption via crafted video filesJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAHighFFmpeg 8.0-8.1.2 Vulkan HEVC decoder stack buffer overflow enables remote code executionJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAHighFFmpeg 2.1-8.1.2 VobSub demuxer heap overflow from .sub/.idx with excessive stream IDsJul 29, 2026Aug 13, 2026Aug 11, 202613 days
Fixed within SLAMediumPartial IO fetch leaves canceled flags set, blocking ublk io_uring cancel completionJul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLAMediumpowerpc/64s race between move_pages PMD migration and munmap hits VM_BUG_ON in pmdp_huge_get_and_clear_fullJul 27, 2026Sep 10, 2026Aug 11, 202615 days
Fixed within SLAHighUse-after-free when querying offloaded BPF map/prog due to netns teardown raceJul 27, 2026Aug 11, 2026Aug 11, 202615 days
Fixed within SLAMediumice: race between ice_free_tx_tstamp_ring and ice_tx_map causes NULL derefJul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLAMediumice: Potential NULL dereference in ice_set_ringparam() error path with TXTIME flag setJul 16, 2026Aug 30, 2026Aug 11, 202626 days
Fixed within SLACriticalAug 10, 2026Aug 17, 2026Aug 11, 20261 day
Fixed within SLAMediumImageMagick <7.1.2-27 magick CLI memory leak on malformed options causes DoSAug 5, 2026Sep 19, 2026Aug 10, 20265 days
Fixed within SLAMediumCrafted image triggers heap buffer over-read in ImageMagick BGR decoder pre-7.1.2-27Aug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAHighKVM: Missing memslot bounds check causes OOB lpage_info access during hugepage recoveryAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAHighGuest-triggered kernel BUG via unaligned ioeventfd datamatch on KVM page-split MMIOAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAHighLinux nx crypto: kernel oops from wrong ctx type passed to nx_crypto_ctx_exitAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAHighgfs2: use-after-free in gfs2_qd_dealloc when superblock freed before RCU callbacks finishAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAHighUse-after-free from PPP protocol timers when HDLC state is freed during detachAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAHighUse-after-free in blk-cgroup __blkcg_rstat_flush via llist_del_all during concurrent blkg releasesAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAHighTIPC decrypt async completion UAF from missing netns ref when crypto_aead_decrypt offloadedAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLACriticalUse-after-free in pNFS pnfs_update_layout() tracepoint after freeing lo with pnfs_put_layout_hdrAug 4, 2026Aug 11, 2026Aug 10, 20266 days
Fixed within SLAHighsched/mmcid: OOB clear_bit from MM_CID_UNSET during per-CPU CID fixupAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAMediumimgpdc irqchip resource leak and dangling chained handlers cause use-after-free, kernel crashesAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAHighrpmsg char: callbacks use freed eptdev after probe failure due to stale privAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAHighOCFS2 accepts oversized group bitmap descriptors causing OOB bitmap access and use-after-freeAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLACritical9p p9_client_walk error drops oldfid reference when clone=false, causing UAF/refcount underflowAug 4, 2026Aug 11, 2026Aug 10, 20266 days
Fixed within SLAHighKVM SVM unbounded destination offset causes page overflow and memcpy overrun in sev_dbg_crypt ENCRYPTAug 4, 2026Aug 19, 2026Aug 10, 20266 days
Fixed within SLAMediumImageMagick JNX parsing integer overflow on 32-bit platforms causes heap buffer overwriteAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAMediumHeap buffer overwrite in ImageMagick fx operation via crafted argument before 7.1.2-27Aug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAMediumfbdev: fb_videomode_to_var NULL deref when new modelist omits current modeAug 4, 2026Sep 18, 2026Aug 10, 20266 days
Fixed within SLAHighfbcon_do_set_font err_out misses hi_font rollback, enabling OOB read/memory leakAug 4, 2026Aug 19, 2026Aug 10, 20266 days

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems