Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-16262
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Estatik < 4.3.3 - Login CSRF

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.

References

Affected products

Estatik Real Estate Plugin
  • <4.3.3
Dismissed
(no matching packages found)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files

File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target), and does not rotate it. But it touches the file, which creates the target. An attacker that has the ability to create the symlink can use this to create an arbitrary file with permissions of the process rotating the files (which may be different from the process that normally writes to the log file that is being rotated). Note that the touch option is disabled by default.

Affected products

File-Rotate-Simple
  • <0.4.0
Dismissed
(no matching packages found)
Permalink CVE-2026-64676
5.7 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo) deployments, the kata-agent enforces an OPA/Rego-based AgentPolicy that must authorize every ttRPC API call, forming the security boundary that prevents an untrusted host from directing the confidential guest. Two ttRPC methods introduced with the mem-agent feature are missing this authorization check, so an untrusted host can invoke them unconditionally regardless of the guest's policy configuration. When mem-agent is enabled (off by default), this lets the host tamper with in-guest memory management by forcing swap, aggressive eviction, or compaction, resulting in attacker-controlled availability and performance degradation of the confidential workload entirely outside the agent-policy boundary. The impact does not include memory disclosure or code execution, and severity is bounded by the precondition that mem-agent must be explicitly enabled. This issue is fixed in version 4.0.0.

Affected products

kata-containers
  • ==< 4.0.0
Dismissed
(no matching packages found)
Permalink CVE-2026-20348
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
ClamAV XAR File Format Processing Memory Corruption Vulnerability

A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that contains XAR content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

Affected products

Cisco Secure Endpoint
  • ==7.5.19
  • ==1.20.2
  • ==6.2.5
  • ==1.11.0
  • ==6.3.7
  • ==8.0.1.21164
  • ==8.1.5.21322
  • ==1.13.1
  • ==7.2.13
  • ==1.22.1
  • ==8.1.5
  • ==7.5.5
  • ==7.4.3.20679
  • ==8.4.1.30307
  • ==7.5.11
  • ==1.15.3
  • ==1.22.3
  • ==1.24.1
  • ==7.2.5
  • ==1.12.3
  • ==1.24.2
  • ==8.1.7
  • ==1.27.0
  • ==1.12.6
  • ==8.4.0
  • ==7.4.1
  • ==1.20.3
  • ==1.17.0
  • ==1.8.0
  • ==6.2.9
  • ==7.5.7
  • ==7.5.20
  • ==1.12.0
  • ==1.6.0
  • ==7.3.3
  • ==8.2.3.30119
  • ==1.14.1
  • ==1.16.2
  • ==6.3.3
  • ==7.5.15.21611
  • ==1.13.0
  • ==8.4.4.30419
  • ==1.24.5
  • ==1.12.1
  • ==1.20.0
  • ==1.25.2
  • ==1.23.0
  • ==6.3.5
  • ==7.1.5
  • ==8.1.3
  • ==7.3.5
  • ==1.24.4
  • ==7.5.9
  • ==1.21.0
  • ==7.2.11
  • ==1.15.2
  • ==1.22.0
  • ==7.5.1.20833
  • ==1.16.3
  • ==1.23.1
  • ==6.2.19
  • ==1.21.2
  • ==1.27.1
  • ==7.5.3
  • ==8.1.7.21512
  • ==7.2.3
  • ==7.4.5
  • ==1.14.0
  • ==1.9.0
  • ==1.8.4
  • ==8.4.1.30298
  • ==1.24.3
  • ==1.24.0
  • ==7.5.17.21680
  • ==1.15.0
  • ==1.18.1
  • ==7.3.15
  • ==8.0.1.21160
  • ==7.3.1
  • ==1.10.2
  • ==1.12.2
  • ==1.20.4
  • ==1.20.7
  • ==1.9.1
  • ==1.26.1
  • ==1.20.1
  • ==7.1.1
  • ==1.20.8
  • ==8.2.1.21612
  • ==1.12.4
  • ==7.3.9
  • ==7.3.13
  • ==7.5.13.21598
  • ==8.4.5.30483
  • ==6.2.3
  • ==1.25.1
  • ==1.16.0
  • ==1.17.2
  • ==1.13.2
  • ==8.2.4.30130
  • ==1.7.0
  • ==1.21.3
  • ==7.4.1.20439
  • ==1.17.1
  • ==8.4.3
  • ==6.1.9
  • ==6.2.1
  • ==1.22.2
  • ==1.10.0
  • ==8.2.1.21650
  • ==8.4.4.30467
  • ==1.27.2
  • ==1.8.1
  • ==1.15.6
  • ==1.19.0
  • ==6.0.7
  • ==1.15.4
  • ==8.1.3.21242
  • ==8.1.7.21417
  • ==1.15.1
  • ==1.18.0
  • ==1.11.1
  • ==7.4.1.20425
  • ==1.26.0
  • ==7.5.13.21586
  • ==6.1.5
  • ==1.16.1
  • ==1.12.5
  • ==6.0.9
  • ==1.20.5
  • ==1.15.5
  • ==6.1.7
  • ==7.5.1.20813
  • ==8.4.2.30317
  • ==1.20.6
  • ==8.1.7.21585
  • ==1.21.1
  • ==1.25.0
  • ==1.12.7
  • ==7.5.21.21732
  • ==7.0.5
  • ==1.10.1
  • ==6.3.1
  • ==1.22.4
  • ==7.2.7
  • ==7.4.3
Dismissed
(exclusively hosted service)
Permalink CVE-2026-56162
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (exclusively hosted service) suggestion
Azure SQL Database Elevation of Privilege Vulnerability

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Affected products

Azure SQL Database
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-62896
9.6 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (exclusively hosted service) suggestion
Microsoft Teams Elevation of Privilege Vulnerability

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

Affected products

Microsoft Teams
  • ==-
Dismissed
(no matching packages found)
Permalink CVE-2026-54205
6.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionality

Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524.

Affected products

TeamDavid
  • =<Rollout 524
Dismissed
(no matching packages found)
Permalink CVE-2026-17601
8.9 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): Low (L)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.

Affected products

Nexus Repository 3
  • <3.95.0
Dismissed
(no matching packages found)
Permalink CVE-2026-20346
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
ClamAV PDF File Format Processing Memory Corruption Vulnerability

A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

Affected products

Cisco Secure Endpoint
  • ==7.5.19
  • ==1.20.2
  • ==6.2.5
  • ==7.2.7
  • ==1.11.0
  • ==8.0.1.21164
  • ==6.3.7
  • ==8.1.5.21322
  • ==2.8.0
  • ==1.13.1
  • ==7.2.13
  • ==1.22.1
  • ==8.1.5
  • ==7.5.5
  • ==2.5.0
  • ==7.4.3.20679
  • ==8.4.1.30307
  • ==2.6.0
  • ==7.5.11
  • ==1.15.3
  • ==1.22.3
  • ==1.24.1
  • ==2.2.0
  • ==7.2.5
  • ==1.12.3
  • ==2.3.0
  • ==2.10.1
  • ==1.24.2
  • ==8.1.7
  • ==2.11.0
  • ==1.27.0
  • ==1.12.6
  • ==8.4.0
  • ==7.4.1
  • ==1.20.3
  • ==1.17.0
  • ==1.8.0
  • ==6.2.9
  • ==7.5.7
  • ==2.4.0
  • ==7.5.20
  • ==1.12.0
  • ==1.6.0
  • ==7.3.3
  • ==2.9.0
  • ==8.2.3.30119
  • ==1.14.1
  • ==1.16.2
  • ==7.5.15.21611
  • ==6.3.3
  • ==1.13.0
  • ==8.4.4.30419
  • ==1.24.5
  • ==1.20.0
  • ==1.25.2
  • ==1.12.1
  • ==1.23.0
  • ==6.3.5
  • ==7.1.5
  • ==2.10.0
  • ==8.1.3
  • ==2.0.0
  • ==7.3.5
  • ==1.24.4
  • ==7.5.9
  • ==1.21.0
  • ==7.2.11
  • ==1.15.2
  • ==1.22.0
  • ==7.5.1.20833
  • ==1.16.3
  • ==1.23.1
  • ==6.2.19
  • ==1.21.2
  • ==1.27.1
  • ==7.5.3
  • ==8.1.7.21512
  • ==7.4.5
  • ==7.2.3
  • ==1.14.0
  • ==1.9.0
  • ==1.8.4
  • ==1.24.3
  • ==1.24.0
  • ==7.5.17.21680
  • ==1.15.0
  • ==1.18.1
  • ==7.3.15
  • ==8.0.1.21160
  • ==1.12.2
  • ==1.10.2
  • ==2.1.0.14
  • ==1.20.4
  • ==1.20.7
  • ==7.3.1
  • ==1.9.1
  • ==1.26.1
  • ==1.20.1
  • ==1.20.8
  • ==7.1.1
  • ==8.2.1.21612
  • ==1.12.4
  • ==7.3.9
  • ==7.3.13
  • ==7.5.13.21598
  • ==8.4.5.30483
  • ==6.2.3
  • ==1.25.1
  • ==1.16.0
  • ==1.17.2
  • ==1.13.2
  • ==8.2.4.30130
  • ==1.7.0
  • ==1.21.3
  • ==7.4.1.20439
  • ==1.17.1
  • ==8.4.3
  • ==6.1.9
  • ==6.2.1
  • ==1.22.2
  • ==1.10.0
  • ==8.2.1.21650
  • ==8.4.4.30467
  • ==1.27.2
  • ==1.8.1
  • ==1.15.6
  • ==1.19.0
  • ==6.0.7
  • ==1.15.4
  • ==8.1.3.21242
  • ==8.1.7.21417
  • ==1.15.1
  • ==1.18.0
  • ==1.11.1
  • ==7.4.1.20425
  • ==1.26.0
  • ==7.5.13.21586
  • ==2.0.1
  • ==1.16.1
  • ==6.1.5
  • ==1.12.5
  • ==2.7.0
  • ==2.0.2
  • ==1.20.5
  • ==1.15.5
  • ==6.1.7
  • ==7.5.1.20813
  • ==6.0.9
  • ==8.4.2.30317
  • ==1.20.6
  • ==8.1.7.21585
  • ==1.21.1
  • ==1.25.0
  • ==1.12.7
  • ==7.5.21.21732
  • ==7.0.5
  • ==1.10.1
  • ==1.1.0
  • ==6.3.1
  • ==1.22.4
  • ==8.4.1.30298
  • ==7.4.3
Dismissed
(no matching packages found)
Permalink CVE-2026-56794
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 4 weeks, 2 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a …

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

Affected products

Dell OpenManage Server Administrator Managed Node for SLES 15
  • <11.1.0.2
Dell OpenManage Server Administrator Managed Node for RHEL 9.4
  • <11.1.0.2
Dell OpenManage Server Administrator Managed Node for RHEL 8.10
  • <11.1.0.2
Dell OpenManage Server Administrator Managed Node (Patch) for Windows
  • <11.1.0.2