Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: python314Packages.uefi-firmware-parser

Found 3 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-42566
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month, 1 week ago Activity log
  • Created suggestion
Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The malformed name does not need to be maliciously crafted — it can arise from ordinary buffer truncation and has been observed occurring naturally in the wild. At least one code path could place a null terminator in the middle of a multibyte sequence, leaving a malformed User.long_name in the node database. The problem surfaced downstream: the iOS app enforced encoding validation and therefore cannot parse a node database once it contains a poisoned entry. This caused BLE sync to enter a fail/retry loop, resulting in loss of control over the affected device. For a typical user managing their radio with the iOS app, the device becomes effectively unusable until the poisoned node ages out of the on-device database, or unless they have an alternate management path (e.g., the Python CLI, which can be used to identify and remove the offending entries manually). Because the malformed name propagates through the mesh, the temporary presence of a single affected node can degrade BLE management for iOS users across a wide geographical area for an extended period. Less technical users have no straightforward recovery path. Starting in version 2.7.23.b246bcd, the firmware has added input sanitization and regression tests demonstrating recovery for already-poisoned devices. The apps have also taken steps to ensure more graceful handling of malformed encoding sequences as well.

Affected products

firmware
  • ==< 2.7.23.b246bcd

Matching in nixpkgs

pkgs.zd1211fw

Firmware for the ZyDAS ZD1211(b) 802.11a/b/g USB WLAN chip

  • nixos-unstable -
    • nixos-unstable-small 1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.5

pkgs.alsa-firmware

Soundcard firmwares from the alsa project

  • nixos-unstable -
    • nixos-unstable-small 1.2.4
  • nixos-26.05 -
    • nixos-26.05-small 1.2.4

pkgs.ivsc-firmware

Firmware binaries for the Intel Vision Sensing Controller

pkgs.gnome-firmware

Tool for installing firmware on devices

  • nixos-unstable -
    • nixos-unstable-small 49.0
  • nixos-26.05 -
    • nixos-26.05-small 49.0

pkgs.linux-firmware

Binary firmware collection packaged by kernel.org

  • nixos-unstable -
  • nixos-26.05 -

pkgs.firmware-manager

Graphical frontend for firmware management

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.5

pkgs.ipw2200-firmware

Firmware for Intel 2200BG cards

  • nixos-unstable -
    • nixos-unstable-small 3.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1

pkgs.rtl8761b-firmware

Firmware for Realtek RTL8761b

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.system76-firmware

Tools for managing firmware updates for system76 devices

  • nixos-unstable -
  • nixos-26.05 -

pkgs.intel2200BGFirmware

Firmware for Intel 2200BG cards

  • nixos-unstable -
    • nixos-unstable-small 3.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1

pkgs.uefi-firmware-parser

Tool for parsing, extracting, and recreating UEFI firmware volumes

  • nixos-unstable -
    • nixos-unstable-small 1.16
  • nixos-26.05 -
    • nixos-26.05-small 1.16

pkgs.nitrokey-pro-firmware

Firmware for the Nitrokey Pro device

  • nixos-unstable -
    • nixos-unstable-small 0.15
  • nixos-26.05 -
    • nixos-26.05-small 0.15

pkgs.armTrustedFirmwareQemu

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.armTrustedFirmwareS905

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.armTrustedFirmwareTools

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nitrokey-start-firmware

Firmware for the Nitrokey Start device

  • nixos-unstable -
    • nixos-unstable-small 13
  • nixos-26.05 -
    • nixos-26.05-small 13

Package maintainers

Untriaged
Permalink CVE-2026-44359
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month, 1 week ago Activity log
  • Created suggestion
Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions. No approval gate exists. Pull requests from external users with author_association: "NONE" triggered the CI workflow automatically. The workflow directly executes attacker-controlled files from the fork checkout. This issue could have resulted in supply chain compromise, self-hosted runner compromise, and/or repository takeover for the repo. This issue is separate from GHSA-6mwm-v2vv-pp96, which addressed a command injection via github.head_ref in the setup job of the same workflow. That fix correctly moved to environment variables. However, the more critical fork checkout vulnerability across the check, build, and build-debian-src jobs was not addressed. Version 2.7.21.1370b23 contains a patch for thie issue.

Affected products

firmware
  • ==< 2.7.21.1370b23

Matching in nixpkgs

pkgs.zd1211fw

Firmware for the ZyDAS ZD1211(b) 802.11a/b/g USB WLAN chip

  • nixos-unstable -
    • nixos-unstable-small 1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.5

pkgs.alsa-firmware

Soundcard firmwares from the alsa project

  • nixos-unstable -
    • nixos-unstable-small 1.2.4
  • nixos-26.05 -
    • nixos-26.05-small 1.2.4

pkgs.ivsc-firmware

Firmware binaries for the Intel Vision Sensing Controller

pkgs.gnome-firmware

Tool for installing firmware on devices

  • nixos-unstable -
    • nixos-unstable-small 49.0
  • nixos-26.05 -
    • nixos-26.05-small 49.0

pkgs.linux-firmware

Binary firmware collection packaged by kernel.org

  • nixos-unstable -
  • nixos-26.05 -

pkgs.firmware-manager

Graphical frontend for firmware management

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.5

pkgs.ipw2200-firmware

Firmware for Intel 2200BG cards

  • nixos-unstable -
    • nixos-unstable-small 3.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1

pkgs.rtl8761b-firmware

Firmware for Realtek RTL8761b

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.system76-firmware

Tools for managing firmware updates for system76 devices

  • nixos-unstable -
  • nixos-26.05 -

pkgs.intel2200BGFirmware

Firmware for Intel 2200BG cards

  • nixos-unstable -
    • nixos-unstable-small 3.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1

pkgs.uefi-firmware-parser

Tool for parsing, extracting, and recreating UEFI firmware volumes

  • nixos-unstable -
    • nixos-unstable-small 1.16
  • nixos-26.05 -
    • nixos-26.05-small 1.16

pkgs.nitrokey-pro-firmware

Firmware for the Nitrokey Pro device

  • nixos-unstable -
    • nixos-unstable-small 0.15
  • nixos-26.05 -
    • nixos-26.05-small 0.15

pkgs.armTrustedFirmwareQemu

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.armTrustedFirmwareS905

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.armTrustedFirmwareTools

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nitrokey-start-firmware

Firmware for the Nitrokey Start device

  • nixos-unstable -
    • nixos-unstable-small 13
  • nixos-26.05 -
    • nixos-26.05-small 13

Package maintainers

Untriaged
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor

Affected products

firmware
  • ==US_AC10V1.0re_V15.03.06.46_multi_TDE01
  • ==US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
  • ==US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
  • ==US_AC6V2.0RTL_V15.03.06.51_multi_T
  • ==US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE

Matching in nixpkgs

pkgs.zd1211fw

Firmware for the ZyDAS ZD1211(b) 802.11a/b/g USB WLAN chip

  • nixos-unstable -
    • nixos-unstable-small 1.5
  • nixos-26.05 -
    • nixos-26.05-small 1.5

pkgs.alsa-firmware

Soundcard firmwares from the alsa project

  • nixos-unstable -
    • nixos-unstable-small 1.2.4
  • nixos-26.05 -
    • nixos-26.05-small 1.2.4

pkgs.ivsc-firmware

Firmware binaries for the Intel Vision Sensing Controller

pkgs.gnome-firmware

Tool for installing firmware on devices

  • nixos-unstable -
    • nixos-unstable-small 49.0
  • nixos-26.05 -
    • nixos-26.05-small 49.0

pkgs.linux-firmware

Binary firmware collection packaged by kernel.org

  • nixos-unstable -
  • nixos-26.05 -

pkgs.firmware-manager

Graphical frontend for firmware management

  • nixos-unstable -
    • nixos-unstable-small 0.1.5
  • nixos-26.05 -
    • nixos-26.05-small 0.1.5

pkgs.ipw2200-firmware

Firmware for Intel 2200BG cards

  • nixos-unstable -
    • nixos-unstable-small 3.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1

pkgs.rtl8761b-firmware

Firmware for Realtek RTL8761b

  • nixos-unstable -
    • nixos-unstable-small
  • nixos-26.05 -
    • nixos-26.05-small

pkgs.system76-firmware

Tools for managing firmware updates for system76 devices

  • nixos-unstable -
  • nixos-26.05 -

pkgs.intel2200BGFirmware

Firmware for Intel 2200BG cards

  • nixos-unstable -
    • nixos-unstable-small 3.1
  • nixos-26.05 -
    • nixos-26.05-small 3.1

pkgs.uefi-firmware-parser

Tool for parsing, extracting, and recreating UEFI firmware volumes

  • nixos-unstable -
    • nixos-unstable-small 1.16
  • nixos-26.05 -
    • nixos-26.05-small 1.16

pkgs.nitrokey-pro-firmware

Firmware for the Nitrokey Pro device

  • nixos-unstable -
    • nixos-unstable-small 0.15
  • nixos-26.05 -
    • nixos-26.05-small 0.15

pkgs.armTrustedFirmwareQemu

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.armTrustedFirmwareS905

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.armTrustedFirmwareTools

Reference implementation of secure world software for ARMv8-A

  • nixos-unstable -
  • nixos-26.05 -

pkgs.nitrokey-start-firmware

Firmware for the Nitrokey Start device

  • nixos-unstable -
    • nixos-unstable-small 13
  • nixos-26.05 -
    • nixos-26.05-small 13