Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2025-30237
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.

References

Affected products

HB610(EU1)
  • <0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n
XX530v(EU1)
  • <0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n
XX530v(US1)
  • <0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n
EX220(BR) V2.0
  • <0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n
EX220(RU) V1.0
  • <0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
EX222(KR) V1.0
  • <0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915
EX520v(EU1)1.0
  • <0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n
HB210(EU1) 1.0
  • <0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n
HB210(US2) 1.0
  • <0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n
HB610(CA) V2.0
  • <0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n
HB710(EU1) 1.0
  • <0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n
HX220(AU) V1.0
  • <0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
HX220(CA) V1.0
  • <0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
HX510(US2) 2.6
  • <0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n
XX530v(BR)v1.0
  • <0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n
XX530v(BR)v2.0
  • <0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n
EX141(EU1) V1.0
  • <1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n
EX141(US1) V1.0
  • <1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n
EX220(US1) V1.0
  • <0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
EX222(EU1) V1.0
  • <0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
EX222(US1) V1.0
  • <0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
EX511(EU1) V2.0
  • <0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n
EX511(US1) V2.0
  • <0.8.0 3.0.0 v607e.0 Build 260424 Rel.27419n
EX520(US1) V1.0
  • <0.7.0 3.0.0 v60b4.0 Build 251229 Rel.84306n
EX521(US1) V1.0
  • <0.3.0 3.0.0 v60e3.0 Build 250925 Rel.66797n
HB410( EU1) 1.0
  • <0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n
HB810(EU1) V2.0
  • <0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n
HX141(EU1) V1.0
  • <1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n
HX220(EU1) V1.0
  • <0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
HX510(EU1) V2.0
  • <0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
HX510(US1) V2.0
  • <0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
HX710(EU1) V1.0
  • <0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n
VX800v(DE) V1.0
  • <800.0.16
XX230v(BR) V1.0
  • <0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n
EX820v(EU1) V1.0
  • <0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n
HB210 Pro(EU1)1.0
  • <0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n
VX1800v(EU1) V1.0
  • <0.14.0 2.0.0 v6092.0 Build 250417 Rel.24761n
EX141(BR) V1.0/1.9
  • <1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n
HC220-G5(BR) V1.30
  • <0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n
HX510(AU) V1.0/2.0
  • <0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
HX510(CA) V1.0/2.0
  • <0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
VX420-G2h(AU) V3.0
  • <0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n
HB610(US2) V2.6/2.0
  • <0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n
HB710(US2) V1.6/1.0
  • <0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n
HX220(US1) V1.0/1.0
  • <0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
HX710 Pro(EU1) V1.0
  • <0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n
EX220(EU1) V1.0/1.20
  • <0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
EX920(US2) V1.6/V1.0
  • <0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n
XC220-G3v(EU1) V2.30
  • <1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n
XC220-G3v(US1) V2.30
  • <1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n
HB210 Pro(US2)1.0/1.6
  • <0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n
EX511(BR) V2.0/2.8/2.9
  • <0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n
HC220-G5(US1) V1.0/1.6
  • <0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n
HC220-G5(EU1) V1.20/1.0
  • <0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n
HB810(US2) V1.0/1.6/2.0/2.6
  • <0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n
EX220(BR) V1.0/1.20/1.28/1.29/1.8
  • <0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
Dismissed
(no matching packages found)
Permalink CVE-2026-21065
4.8 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 …

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

Affected products

Samsung Mobile Devices
  • *
Dismissed
(max. allowed matches exceeded)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
drm/xe/guc: Fix buffer overflow in steered register list allocation

In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix buffer overflow in steered register list allocation The size calculation for the steered register extarray uses only the geometry DSS mask (g_dss_mask) to determine the number of entries to allocate: total = bitmap_weight(gt->fuse_topo.g_dss_mask, ...) * steer_reg_num; However, the filling loop uses for_each_dss_steering(), which iterates over for_each_dss(), defined as the union of g_dss_mask and c_dss_mask (geometry + compute DSS). On platforms with compute-only DSS bits, the loop writes past the allocated buffer, corrupting adjacent slab objects. This manifests as list_del corruption and SLUB redzone overwrites during drm_managed_release on device unbind, since the overflow corrupts the drmres list_head of neighboring allocations. Fix by computing the allocation size using the union of both DSS masks, matching the iteration pattern of for_each_dss_steering(). -- v2: - use bitmap_weighted_or() (Zhanjun) (cherry picked from commit 0a78a44f4901aa6c9263e66be7fce02282f1109f)

Affected products

Linux
  • <632ecc90e1ca5d3b6822bb4d08f84a175b6c42c0
  • <a9a020f3c11eba6573b699f9cf9245a51b025ade
  • =<*
  • =<6.18.*
  • <6.13
  • ==6.13
  • =<7.1.*
  • <b485bfb45555163bfa5f565d6a3415fcb3035b02
Dismissed
(max. allowed matches exceeded)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM The drm gpuvm code doesn't protect find operation against map operation, and the driver needs to ensure a map operation shouldn't happen when a find operation is in progress. In some cases a find operation will be in progress when doing map/unmap operations, and the find operation will do a NULL pointer dereference. An example of the stack trace of such NULL dereference is shown below: ``` Unable to handle kernel access to user memory without uaccess routines at virtual address 0000000000000010 [<ffffffff01e989d4>] drm_gpuva_find+0x28/0x6c [drm_gpuvm] [<ffffffff01ed3a40>] pvr_vm_unmap+0x34/0x68 [powervr] [<ffffffff01ec69da>] pvr_ioctl_vm_unmap+0x2e/0x50 [powervr] [<ffffffff8080ce0a>] drm_ioctl_kernel+0x8e/0xdc [<ffffffff8080d016>] drm_ioctl+0x1be/0x3e0 [<ffffffff802bec3e>] __riscv_sys_ioctl+0xba/0xc4 [<ffffffff80d858b2>] do_trap_ecall_u+0x23e/0x3f4 [<ffffffff80d92288>] handle_exception+0x168/0x174 ``` As all occurences of drm_gpuva_find*() are already guarded by vm_ctx->lock, make pvr_vm_map() to acquire this lock to prevent disturbing any find operation. This fixes the NULL deference problem in drm_gpuva_find*().

Affected products

Linux
  • ==6.8
  • <6.8
  • =<*
  • <1f1f2618e44b21a7d4eb30d3bbd7e015ffbbbadf
  • <15f58d44c24477a6ebffa44ec05207b81cfa55d9
  • =<6.18.*
  • =<6.12.*
  • <6253bb56bb2ebdf317d8b599ce737a2510cc2e17
  • =<7.1.*
  • <17e2030f37600994440f875dc410615d5c66ee6d
Dismissed
(no matching packages found)
Permalink CVE-2026-71992
9.3 CRITICAL
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
MSI Radix AXE6600 v781521 Command Injection via macfilter

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

Affected products

Radix AXE6600
  • =<v781521
Dismissed
(no matching packages found)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
None

None

Affected products

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered

In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered sata_dwc_enable_interrupts() is called before platform_get_irq() and ata_host_activate(), leaving the SATA controller's interrupt mask enabled without a registered handler. If a later step fails (irq request, phy init, etc.) or if the controller asserts an interrupt during probe, the irq line may fire with no handler, causing a spurious interrupt storm. Move sata_dwc_enable_interrupts() after ata_host_activate() so that interrupts are only unmasked once the handler is registered and the core is fully initialized.

Affected products

Linux
  • <fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4
  • <4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0
  • <23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda
  • <5d0797d6940b8dc894f950c52f7af0b42cb55ed0
  • =<6.6.*
  • =<*
  • <daa80b422ed920a3c0c45153020b0ad7af7fb5a5
  • <2.6.36
  • =<6.18.*
  • =<6.12.*
  • =<7.1.*
  • ==2.6.36
Dismissed
(no matching packages found)
Permalink CVE-2026-72740
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interpolates its domain into the ssh-keyscan command from addHostToKnownHostsCommand without shell quoting, allowing an authenticated member with service deployment permission and an attached SSH key to execute arbitrary commands on the Dokploy host during deployment. This issue is fixed in version 0.29.13.

Affected products

dokploy
  • ==< 0.29.13
Dismissed
(max. allowed matches exceeded)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
drm/amdgpu: Release VFCT ACPI table reference

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Release VFCT ACPI table reference amdgpu_acpi_vfct_bios() fetches the VFCT table with acpi_get_table() but never releases it. acpi_get_table() takes a reference on the table (incrementing its validation_count and mapping it on the 0->1 transition); without a paired acpi_put_table() the mapping is leaked on every call, whether or not a matching VBIOS image is found. Route all exit paths after the table is acquired through a common acpi_put_table(). The VBIOS image is copied out with kmemdup() before the table is released, so it remains valid for the caller. (cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)

Affected products

Linux
  • <7.1.6
  • <65bff26617607c1331283232016c0e89088c5b78
  • <312278b3091912fa56a6a587609f17dcb33465c2
  • =<*
  • <9b7de3ee5d2c5ee2a706e5f7ca0126f4fbea4da8
  • =<6.18.*
  • <6.18.42
  • =<7.1.*
Dismissed
(no matching packages found)
Permalink CVE-2026-72735
9.9 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 3 weeks, 6 days ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interpolates the resulting yamlStr into an echo command executed through execAsyncRemote. Single quotes in redirect regex and replacement fields, basic authentication usernames, domain host values, or middleware configuration can terminate the shell quoting and execute arbitrary commands on managed remote servers with the configured SSH user's privileges. This vulnerability is caused by an incomplete fix for CVE-2026-45630. This issue is fixed in version 0.29.13.

Affected products

dokploy
  • ==< 0.29.13