Nixpkgs Security Tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to remove a suggestion from the queue.

created 5 hours ago
Use After Free in Secure Processor

Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.

Affected products

Snapdragon
  • ==X2000086
  • ==X2000090
  • ==X2000094
  • ==FastConnect 7800
  • ==WCD9378C
  • ==X2000092
  • ==X2000077
  • ==WCD9380
  • ==Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)
  • ==WSA8840
  • ==WSA8835
  • ==WCD9385
  • ==WSA8830
  • ==WSA8845H
  • ==QCC2072
  • ==SC8380XP
  • ==WSA8845
  • ==XG101032
  • ==FastConnect 6900
  • ==XG101002
  • ==XG101039

Matching in nixpkgs

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips

created 5 hours ago
Codex Special:Block vulnerable to message key XSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

Affected products

MediaWiki
  • <1.39.14, 1.43.4, 1.44.1

Matching in nixpkgs

Package maintainers

created 5 hours ago
vLLM leaks a heap address when PIL throws an error

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.

Affected products

vllm
  • ==>= 0.8.3, < 0.14.1

Matching in nixpkgs

pkgs.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

pkgs.pkgsRocm.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

pkgs.python312Packages.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

pkgs.python313Packages.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

pkgs.pkgsRocm.python3Packages.vllm

High-throughput and memory-efficient inference and serving engine for LLMs

Package maintainers

created 5 hours ago
Open5GS CreateBearerRequest s5c-handler.c sgwc_s5c_handle_create_bearer_request assertion

A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function sgwc_s5c_handle_create_bearer_request of the file /src/sgwc/s5c-handler.c of the component CreateBearerRequest Handler. Performing a manipulation results in reachable assertion. Remote exploitation of the attack is possible. The exploit is now public and may be used. To fix this issue, it is recommended to deploy a patch. The issue report is flagged as already-fixed.

Affected products

Open5GS
  • ==2.7.5
  • ==2.7.1
  • ==2.7.6
  • ==2.7.2
  • ==2.7.3
  • ==2.7.0
  • ==2.7.4

Matching in nixpkgs

pkgs.open5gs-webui

4G/5G core network components

Package maintainers

created 5 hours ago
Outline 1.6.0 - Unquoted Service Path

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with LocalSystem permissions.

Affected products

Outline
  • ==1.6.0

Matching in nixpkgs

pkgs.outline

Fastest wiki and knowledge base for growing teams. Beautiful, feature rich, and markdown compatible

pkgs.python312Packages.outlines

Structured text generation

pkgs.typstPackages.suboutline_0_1_0

An outline function just for one section and nothing else

pkgs.typstPackages.suboutline_0_2_0

An outline function just for one section and nothing else

pkgs.typstPackages.suboutline_0_3_0

An outline function just for one section and nothing else

pkgs.mplus-outline-fonts.osdnRelease

M+ Outline Fonts (legacy OSDN release)

pkgs.python312Packages.outlines-core

Structured text generation (core)

pkgs.python314Packages.outlines-core

Structured text generation (core)

pkgs.pkgsRocm.python3Packages.outlines

Structured text generation

pkgs.typstPackages.outline-summaryst_0_1_0

A basic template for including a summary for each entry in the table of contents. Useful for writing books

pkgs.pkgsRocm.python3Packages.outlines-core

Structured text generation (core)

Package maintainers

created 5 hours ago
Integer Overflow or Wraparound in Automotive

Memory corruption when calculating oversized partition sizes without proper checks.

Affected products

Snapdragon
  • ==QCA8695AU
  • ==QCA6688AQ
  • ==QAM8255P
  • ==QAM8295P
  • ==SA8195P
  • ==QCA6574AU
  • ==SA8540P
  • ==SA8155P
  • ==SA6150P
  • ==QCA6595AU
  • ==SA8775P
  • ==QAMSRV1M
  • ==QCA6696
  • ==SRV1L
  • ==SA9000P
  • ==SA6145P
  • ==SA8145P
  • ==SA8620P
  • ==SA8770P
  • ==QAM8650P
  • ==QAM8620P
  • ==SA6155P
  • ==QAMSRV1H
  • ==QAM8775P
  • ==SA8650P
  • ==SA8255P
  • ==SA7775P
  • ==SRV1M
  • ==SA8150P
  • ==SA7255P
  • ==SA8295P
  • ==QCA6797AQ
  • ==QCA6595
  • ==QCA6698AQ
  • ==SRV1H

Matching in nixpkgs

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips

created 5 hours ago
Buffer Copy Without Checking Size of Input in Camera

Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.

Affected products

Snapdragon
  • ==WSA8845H
  • ==X2000086
  • ==X2000090
  • ==X2000092
  • ==X2000077
  • ==X2000094
  • ==WSA8845
  • ==FastConnect 7800
  • ==XG101032
  • ==WSA8840
  • ==WCD9378C
  • ==Cologne
  • ==XG101002
  • ==XG101039

Matching in nixpkgs

pkgs.snapdragon-profiler

Profiler for Android devices running Snapdragon chips

created 5 hours ago
Libxml2: memory leak leading to local denial of service in xmllint interactive shell

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.

Affected products

rhcos
libxml2

Matching in nixpkgs

pkgs.python314Packages.libxml2

XML parsing library for C

pkgs.perl5Packages.AlienLibxml2

Install the C libxml2 library on your system

pkgs.perl540Packages.AlienLibxml2

Install the C libxml2 library on your system

pkgs.tests.pkg-config.defaultPkgConfigPackages."libxml-2.0"

Test whether libxml2-2.14.4-unstable-2025-06-20 exposes pkg-config modules libxml-2.0

Package maintainers

created 5 hours ago
Open5GS SGWC s11-handler.c assertion

A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c of the component SGWC. Such manipulation leads to reachable assertion. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. A patch should be applied to remediate this issue. The issue report is flagged as already-fixed.

Affected products

Open5GS
  • ==2.7.5
  • ==2.7.1
  • ==2.7.6
  • ==2.7.2
  • ==2.7.3
  • ==2.7.0
  • ==2.7.4

Matching in nixpkgs

pkgs.open5gs-webui

4G/5G core network components

Package maintainers

created 5 hours ago
Free5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereference

A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the file internal/sbi/processor/smpolicy.go. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is df535f5524314620715e842baf9723efbeb481a7. Applying a patch is the recommended action to fix this issue.

Affected products

pcf
  • ==1.4.1
  • ==1.4.0

Matching in nixpkgs

pkgs.bdftopcf

Converts X font from Bitmap Distribution Format to Portable Compiled Format

pkgs.xorg.bdftopcf

Converts X font from Bitmap Distribution Format to Portable Compiled Format

pkgs.python312Packages.pcffont

Library for manipulating Portable Compiled Format (PCF) Fonts

pkgs.python313Packages.pcffont

Library for manipulating Portable Compiled Format (PCF) Fonts

pkgs.python314Packages.pcffont

Library for manipulating Portable Compiled Format (PCF) Fonts

Package maintainers