Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-66039
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.

Affected products

FFmpeg
  • =<8.1.2
  • ==aafb5c655edc76a753275c383ebb139feb032718
Dismissed
(no matching packages found)
Permalink CVE-2026-16799
5.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Improper access control in the automation tests and workflows features …

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

Affected products

PowerShell Universal
  • <2026.2.3
Dismissed
(max. allowed matches exceeded)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()

In the Linux kernel, the following vulnerability has been resolved: power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() Move of_node_put(dn) after the of_match_node() call, which still needs the node pointer. The node reference is correctly released after use.

Affected products

Linux
  • =<6.1.*
  • <93c7ee139721936b6fa717572e74d3994603ae13
  • <d109e72f3fbccb540473285d17d7519584f7f76e
  • <2205275be9be981e70ff29610b0117d8853fac70
  • <3928ae803dee044b01076c478c279c0bd54164cd
  • <5.15
  • <cdda7d384c05485a232ae9a849f6445accb095bf
  • =<5.15.*
  • =<7.1.*
  • <c04d606f8b35ee7d3ed243f63893a607e9d6c0bc
  • =<6.18.*
  • =<*
  • ==5.15
  • =<6.6.*
  • =<6.12.*
  • <8eec545cde69e46e9a1d2b7d915ce4f5df85b3bd
Dismissed
(max. allowed matches exceeded)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
octeontx2-af: CGX: add bounds check to cgx_speed_mbps index

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index cgx_speed_mbps has 13 elements but RESP_LINKSTAT_SPEED can yield values 0-15. If it returns a value >= 13, this causes an out-of-bounds array access. Add a bounds check and default to speed 0 if the index is out of range.

Affected products

Linux
  • <47a4cf2229be379cf88f92e32e1240337cd6273f
  • =<6.1.*
  • <4.20
  • <2c3d26b4a62454945ba9ef3af3174d3e40e7afef
  • =<*
  • <93d3dc81098cd60fb74d434ba7985ddfd9de5acb
  • =<5.15.*
  • =<5.10.*
  • <985b5e38ac4f4d5ff03c8bfd8484353b440a1579
  • =<6.18.*
  • ==4.20
  • <e043017ac429caee73bd30c5a725659f1a3a4568
  • <8201bf45cc7c1c1a09290c4db8ab1e19801f8fec
  • <94071141f00bc414e8f8f7f5db3b5143d535299f
  • =<6.12.*
  • =<6.6.*
  • <c0bf0a4f3f1f5f57aa83e1400ba4f56f0abfd542
  • =<7.0.*
Dismissed
(exclusively hosted service)
Permalink CVE-2026-54120
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month, 1 week ago Activity log
  • Created & dismissed (exclusively hosted service) suggestion
Microsoft Surface Remote Code Execution Vulnerability

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

Affected products

Surface Management Services
  • ==-
Dismissed
(exclusively hosted service)
Permalink CVE-2026-56191
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month, 1 week ago Activity log
  • Created & dismissed (exclusively hosted service) suggestion
Microsoft Exchange Online Tampering Vulnerability

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

References

Affected products

Microsoft Exchange Online
  • ==-
Dismissed
(max. allowed matches exceeded)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
LoongArch: Report dying CPU to RCU in stop_this_cpu()

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Report dying CPU to RCU in stop_this_cpu() This is a port of MIPS commit 9f3f3bdc6d9dac1 ("MIPS: smp: report dying CPU to RCU in stop_this_cpu()"). smp_send_stop() parks all secondary CPUs in stop_this_cpu(). And the function marks the CPU offline for the scheduler via set_cpu_online(false) but never informs RCU, so RCU keeps expecting a quiescent state from CPUs that are now spinning forever with interrupts disabled. As long as nothing waits for an RCU grace period after smp_send_stop() this is harmless, which is why it went unnoticed. However, since commit 91840be8f710370 ("irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT"), irq_work_sync() calls synchronize_rcu() on architectures without an irq_work self-IPI, i.e. where arch_irq_work_has_interrupt() returns false. Any irq_work_sync() issued in the reboot/shutdown/halt path after smp_send_stop() then blocks on a grace period that can never complete, hanging the reboot: WARNING: CPU: 0 PID: 15 at kernel/irq_work.c:144 irq_work_queue_on ... rcu: INFO: rcu_sched detected stalls on CPUs/tasks: rcu: Offline CPU 1 blocking current GP. rcu: Offline CPU 2 blocking current GP. rcu: Offline CPU 3 blocking current GP. This issue needs some hacks to reproduce, and it was not noticed on LoongArch because arch_irq_work_has_interrupt() usually returns true. Call rcutree_report_cpu_dead() once interrupts are disabled, mirroring the generic CPU-hotplug offline path, so RCU stops waiting on the parked CPUs and grace periods can still complete. LoongArch shuts down all CPUs here without going through the CPU-hotplug mechanism, so this report is not otherwise issued.

Affected products

Linux
  • <6.18.38
  • <f2539c56c74691e7a88af6372ba2b48c06ed2fe4
  • =<*
  • <0833b2b84c2fc1387f8165f0cbf6a02d67f647a5
  • =<6.12.*
  • <7.1
  • =<6.1.*
  • <7.1
  • =<6.6.*
  • <1fa22de588a65880d6fe54c38c87fffe7d519f60
  • <90e254f18b8c224460082329dd5c42fd30995c2f
  • <a0269e928728f970c782319fee53d92d4ea4e512
  • =<7.1.*
  • <6.12.95
  • <6.6.145
  • ==7.1
  • <6.1.178
  • <262dadc619e69ebeb97affd334cd1078a9704e98
  • =<6.18.*
  • ==81b582784518196eff1050212a046bc29d3a05dd
Dismissed
(max. allowed matches exceeded)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
netfs: Fix overrun check in netfs_extract_user_iter()

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get included in the iterator constructed at the end of the function. If there was an overfill, memory corruption has already happened.

Affected products

Linux
  • <6.3
  • <0ef37eef83fad3542ee06db2940433ae1a92b39d
  • <afeb32d9bf9aaeea51d0f723a19f14afb73bd94d
  • =<*
  • <00efe58bbdcc93272d579ca24bfc912563f4a204
  • ==6.3
  • =<6.18.*
  • <f48b9157f0f611fa436c360648603d5ded719b12
  • <96cc3beb2390ba9f9c128c5733c0ccfe450dd4f9
  • =<6.6.*
  • =<6.12.*
  • =<7.0.*
Dismissed
(max. allowed matches exceeded)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
wifi: mac80211: consume only present negotiated TTLM maps

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: consume only present negotiated TTLM maps ieee80211_tid_to_link_map_size_ok() validates negotiated TTLM elements against the number of link-map entries indicated by link_map_presence. ieee80211_parse_neg_ttlm() must consume the same layout. The parser advanced its cursor for every TID, including TIDs whose presence bit is clear and therefore have no map bytes in the element. A sparse map can then make a later present TID read past the validated element. The bad bytes land in neg_ttlm->{up,down}link[tid] but are gated by valid_links before being applied to driver state, so a peer cannot turn the read into a policy change. Under KUnit + KASAN with an exact-sized element allocation the OOB read is reported as a slab-out-of-bounds; whether the same trigger fires under the production RX path depends on surrounding allocator state. Advance the cursor only when the current TID has a map present.

Affected products

Linux
  • <f7d395dc5008168ac5b9c1ac2791e59a6078cca1
  • <2becaaeebe230ade1fcd5d0f1cde4d6ee93ec78f
  • <a6e6ccd5bd07155c2add6c74ce1a5e68ad3b95ea
  • <6.9
  • =<*
  • =<6.18.*
  • ==6.9
  • =<6.12.*
  • =<7.0.*
  • <2dd9304727c7041df0a599595910bdbe02ad03c5
Dismissed
(max. allowed matches exceeded)
created 1 month, 1 week ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
Input: elan_i2c - validate firmware size before use

In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use Ensure that the firmware file is large enough to contain the expected number of pages and the signature (which resides at the end of the firmware blob) before accessing them to prevent potential out-of-bounds reads.

Affected products

Linux
  • <bf769358419e00344c1b16fa034d058f563d46a1
  • =<*
  • =<5.10.*
  • =<6.12.*
  • =<6.1.*
  • <3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb
  • <7.0.12
  • <5.10.259
  • <6.18.35
  • <331d49b4e1c9efe4479bbd22922dfcdd8c64be7b
  • =<6.6.*
  • <47b52b98edfe34d0249e72f815215ef24311c3a3
  • <6.6.143
  • <5.15.210
  • <6.1.176
  • <48b0aa9c08a3ac8e0c0345b7ca581f552324e460
  • <6.12.93
  • <d97baee9590edf303b3eca432e61de9320834fe1
  • <c2c3b33b3c0bf2c9427c0926817ef5ffac50de6f
  • =<5.15.*
  • =<6.18.*
  • =<7.0.*
  • <76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634