Updated 23:01
Determinate Secure Packages distribution
secure-packages-rollingSupportedAvailable for use in production environments and covered by our standard service-level agreement (SLA).FIPS supportedA FIPS distribution is available for environments that require cryptography compliant with Federal Information Processing Standards.ContinuousCovered continuously, with no end date: as it follows Nixpkgs, every CVE in it gets a fix within our service-level agreement (SLA): 7 days for critical, 15 for high, 45 for medium, and 90 for low.
Built on Nixpkgs as it moves. Available for use in production environments and covered by our standard service-level agreement (SLA).
Fixed within SLA
210
last 30 days
Fixed within SLA
24
last 7 days
Open
27
not yet fixed but still within SLA
Overdue
0
open
Missed SLA
0
last 30 days
Use this distribution
Customers onlyDeterminate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.
Email sales@determinate.systemsStandardflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling/0";
}FIPS variant
FIPS variantflake.nix
{
inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-rolling-fips/0";
}In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.
237 CVEs tracked
| CVE | Status | Severity | Summary | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Critical | Chrome <151.0.7922.72 WebSocket input validation bug enables sandbox escape from compromised renderer | Aug 5, 2026 | Aug 12, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Android Chrome WebView <151.0.7922.72: insufficient input validation enables cross-origin data leak | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | FedCM in Chrome <151.0.7922.72 allows remote same-origin policy bypass via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | iOS Chrome pre-151.0.7922.72 cross-origin data leak via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome iOS <151.0.7922.72: Insufficient input validation enables UXSS script/HTML injection via malicious traffic | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome before 151.0.7922.72 Presentation policy flaw allowed remote navigation bypass via crafted HTML | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Chrome Extensions security UI bug allowed spoofing via malicious extension before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | Medium | Blink same-origin policy bypass via crafted HTML in Chrome before 151.0.7922.72 | Aug 5, 2026 | Sep 19, 2026 | Aug 11, 2026 | 6 days | |
| Fixed within SLA | High | Insufficient input validation in Chrome Network enables sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Medium | Chrome pre-151.0.7922.72 SiteIsolation flaw allows compromised renderer to bypass isolation via crafted HTML | Aug 7, 2026 | Sep 21, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | V8 use-after-free in Chrome <151.0.7922.72 allows sandboxed remote code execution via crafted HTML page | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Chrome Navigation use-after-free allowed sandbox escape via crafted HTML (pre-151.0.7922.72) | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Critical use-after-free in Chrome Ozone pre-151.0.7922.72 enables remote crafted-HTML sandbox escape | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Critical ANGLE input validation flaw enables remote sandbox escape via crafted HTML in Chrome <151.0.7922.72 | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Critical race in Chrome Updater on Mac pre-151.0.7922.72 enables local privilege escalation | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Critical Skia use-after-free in Google Chrome <151.0.7922.72 enables sandbox escape via crafted HTML | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | Critical | Chrome <151.0.7922.72: Views use-after-free enables sandbox escape via crafted HTML | Aug 7, 2026 | Aug 14, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | Chrome Compositing use-after-free pre-151.0.7922.72 enables sandbox escape via crafted HTML | Aug 7, 2026 | Aug 22, 2026 | Aug 11, 2026 | 4 days | |
| Fixed within SLA | High | FFmpeg ADX decoder OOB read/write on mid-stream extradata channel change (v4.4–8.1.2) | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 0.6.3–8.1.2 RTP/ASF demuxer infinite loop DoS in rtp_asf_fix_header | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 0.7.1–8.1.2 S/PDIF muxer out-of-bounds read via crafted DTS core_size | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 4.4–8.1.2 NVDEC double-free enables memory corruption via crafted video files | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 8.0-8.1.2 Vulkan HEVC decoder stack buffer overflow enables remote code execution | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | High | FFmpeg 2.1-8.1.2 VobSub demuxer heap overflow from .sub/.idx with excessive stream IDs | Jul 29, 2026 | Aug 13, 2026 | Aug 11, 2026 | 13 days | |
| Fixed within SLA | Medium | Partial IO fetch leaves canceled flags set, blocking ublk io_uring cancel completion | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Medium | powerpc/64s race between move_pages PMD migration and munmap hits VM_BUG_ON in pmdp_huge_get_and_clear_full | Jul 27, 2026 | Sep 10, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | High | Use-after-free when querying offloaded BPF map/prog due to netns teardown race | Jul 27, 2026 | Aug 11, 2026 | Aug 11, 2026 | 15 days | |
| Fixed within SLA | Medium | ice: race between ice_free_tx_tstamp_ring and ice_tx_map causes NULL deref | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Medium | ice: Potential NULL dereference in ice_set_ringparam() error path with TXTIME flag set | Jul 16, 2026 | Aug 30, 2026 | Aug 11, 2026 | 26 days | |
| Fixed within SLA | Critical | Aug 10, 2026 | Aug 17, 2026 | Aug 11, 2026 | 1 day | ||
| Fixed within SLA | Medium | ImageMagick <7.1.2-27 magick CLI memory leak on malformed options causes DoS | Aug 5, 2026 | Sep 19, 2026 | Aug 10, 2026 | 5 days | |
| Fixed within SLA | Medium | Crafted image triggers heap buffer over-read in ImageMagick BGR decoder pre-7.1.2-27 | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | KVM: Missing memslot bounds check causes OOB lpage_info access during hugepage recovery | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Guest-triggered kernel BUG via unaligned ioeventfd datamatch on KVM page-split MMIO | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Linux nx crypto: kernel oops from wrong ctx type passed to nx_crypto_ctx_exit | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | gfs2: use-after-free in gfs2_qd_dealloc when superblock freed before RCU callbacks finish | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Use-after-free from PPP protocol timers when HDLC state is freed during detach | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | Use-after-free in blk-cgroup __blkcg_rstat_flush via llist_del_all during concurrent blkg releases | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | TIPC decrypt async completion UAF from missing netns ref when crypto_aead_decrypt offloaded | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Critical | Use-after-free in pNFS pnfs_update_layout() tracepoint after freeing lo with pnfs_put_layout_hdr | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | sched/mmcid: OOB clear_bit from MM_CID_UNSET during per-CPU CID fixup | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | imgpdc irqchip resource leak and dangling chained handlers cause use-after-free, kernel crashes | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | rpmsg char: callbacks use freed eptdev after probe failure due to stale priv | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | OCFS2 accepts oversized group bitmap descriptors causing OOB bitmap access and use-after-free | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Critical | 9p p9_client_walk error drops oldfid reference when clone=false, causing UAF/refcount underflow | Aug 4, 2026 | Aug 11, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | KVM SVM unbounded destination offset causes page overflow and memcpy overrun in sev_dbg_crypt ENCRYPT | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | ImageMagick JNX parsing integer overflow on 32-bit platforms causes heap buffer overwrite | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | Heap buffer overwrite in ImageMagick fx operation via crafted argument before 7.1.2-27 | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | Medium | fbdev: fb_videomode_to_var NULL deref when new modelist omits current mode | Aug 4, 2026 | Sep 18, 2026 | Aug 10, 2026 | 6 days | |
| Fixed within SLA | High | fbcon_do_set_font err_out misses hi_font rollback, enabling OOB read/memory leak | Aug 4, 2026 | Aug 19, 2026 | Aug 10, 2026 | 6 days |
Make CVE remediation our job, not yours.
Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.