Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2025-47383
7.2 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Missing Cryptographic Step in Data Modem

Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

Affected products

Snapdragon
  • ==WSA8840
  • ==SM8635P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==WCN3620
  • ==QCA9377
  • ==QCA9367
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==Snapdragon 1100 Wearable Platform
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SD626
  • ==Snapdragon X32 5G Modem-RF System
  • ==Qualcomm 215 Mobile Platform
  • ==WSA8845H
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==WSA8830
  • ==SM7550P
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==QCS4290
  • ==AR8035
  • ==QCA6584
  • ==QCN9024
  • ==WCD9370
  • ==Snapdragon X55 5G Modem-RF System
  • ==WCN7880
  • ==QFW7114
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==Snapdragon 7c Compute Platform
  • ==FastConnect 6900
  • ==QCA6564A
  • ==SDX71M
  • ==QCA6564AU
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==QCN6224
  • ==WCD9360
  • ==Snapdragon 680 4G Mobile Platform
  • ==WCD9380
  • ==SW6100P
  • ==WCN3910
  • ==Snapdragon 888 5G Mobile Platform
  • ==Snapdragon X5 LTE Modem
  • ==WCN3615
  • ==CSRA6640
  • ==Snapdragon 429 Mobile Platform
  • ==Snapdragon 820 Automotive Platform
  • ==CSRB31024
  • ==WCD9390
  • ==QCA6595AU
  • ==SDM429W
  • ==Snapdragon 460 Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon X35 5G Modem-RF System
  • ==Vision Intelligence 200 Platform
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==FastConnect 7800
  • ==QCM6490
  • ==FastConnect 6200
  • ==Snapdragon Auto 5G Modem-RF
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==FastConnect 6700
  • ==SW5100
  • ==SDA660
  • ==Vision Intelligence 100 Platform
  • ==Snapdragon 820Am
  • ==QCA6584AU
  • ==WSA8835
  • ==SM7325P
  • ==WCD9330
  • ==SM8635
  • ==SM8750P
  • ==G1 Gen 1
  • ==WCD9378
  • ==Smart Display 200 Platform
  • ==WCD9341
  • ==SM8550P
  • ==WCD9326
  • ==Snapdragon 8cx Compute Platform "Poipu Pro"
  • ==Themisto
  • ==WCD9371
  • ==WCN7860
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==Snapdragon 625 Mobile Platform
  • ==WCN3950
  • ==CSRA6620
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==Snapdragon 685 4G Mobile Platform
  • ==Snapdragon 865 5G Mobile Platform
  • ==Snapdragon 480 5G Mobile Platform
  • ==WCN3680B
  • ==9207 LTE Modem
  • ==MDM9250
  • ==SD662
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==QCA6174A
  • ==SD 8 Gen1 5G
  • ==Snapdragon 626 Mobile Platform
  • ==QCA8081
  • ==Snapdragon 660 Mobile Platform
  • ==QCM5430
  • ==SM6650P
  • ==MDM9640
  • ==Snapdragon X53 5G Modem-RF System
  • ==QCM6125
  • ==QEP8111
  • ==QCA6797AQ
  • ==SDX57M
  • ==QCA6420
  • ==QCM4490
  • ==Milos
  • ==Snapdragon X72 5G Modem-RF System
  • ==QCA6574AU
  • ==QCS8550
  • ==Snapdragon 8cx Gen 2 5G Compute Platform
  • ==QCA6698AU
  • ==WSA8815
  • ==Netrani
  • ==QCN6024
  • ==SM7550
  • ==SM6250
  • ==Snapdragon 1200 Wearable Platform
  • ==5G Fixed Wireless Access Platform
  • ==Snapdragon X70 Modem-RF System
  • ==QCA6688AQ
  • ==QCM4325
  • ==C-V2X 9150
  • ==SM8475P
  • ==Snapdragon 8cx Compute Platform
  • ==Orne
  • ==Snapdragon X65 5G Modem-RF System
  • ==Snapdragon 8c Compute Platform "Poipu Lite"
  • ==WCN6650
  • ==Snapdragon 778G 5G Mobile Platform
  • ==WCN3660B
  • ==WCD9306
  • ==QFW7124
  • ==Robotics RB2 Platform
  • ==QCM2290
  • ==SnapdragonAuto 4GModem
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==WCD9385
  • ==SM7675P
  • ==QMP1000
  • ==WCD9375
  • ==AQT1000
  • ==FWA Gen 3 Ultra Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==QCA6698AQ
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==Snapdragon 8cx Gen 2 5G Compute Platform "Poipu Pro"
  • ==Snapdragon 782G Mobile Platform
  • ==WCD9335
  • ==WCN7861
  • ==SDX61
  • ==APQ8098
  • ==QCA6696
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==MDM9628
  • ==QCN9012
  • ==SW6100
  • ==WCN7881
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==SM7435
  • ==Snapdragon 8 Elite
  • ==QCA6678AQ
  • ==WSA8810
  • ==QCA6574A
  • ==SM7675
  • ==SM7635P
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==QCN6274
  • ==WCN3988
  • ==Palawan25
  • ==Snapdragon X12 LTE Modem
  • ==SW5100P
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==WSA8845
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==FSM100 Platform
  • ==Snapdragon X80 5G Modem-RF System
  • ==QCC710
  • ==QCN9011
  • ==SM8650Q
  • ==WCD9395
  • ==Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"
  • ==MDM8207
  • ==QCA8337
  • ==QCS2290
  • ==WCN3990
  • ==QCA6574
  • ==Snapdragon X75 5G Modem-RF System
  • ==QCA6391
  • ==Snapdragon 870 5G Mobile Platform
  • ==WCN6755
  • ==Snapdragon 662 Mobile Platform
  • ==QCS4490
  • ==WSA8832
  • ==9206 LTE Modem
  • ==Snapdragon 7c Gen 2 Compute Platform "Rennell Pro"
  • ==WCD9340
  • ==QCA6430
  • ==FastConnect 6800
  • ==WCN3980
  • ==Vision Intelligence 400 Platform
  • ==SM6225P

Matching in nixpkgs

Permalink CVE-2025-47375
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Use After Free in Automotive Audio

Memory corruption while handling different IOCTL calls from the user-space simultaneously.

Affected products

Snapdragon
  • ==WSA8840
  • ==SM8635P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCA9377
  • ==QCA8695AU
  • ==QCA9367
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon X32 5G Modem-RF System
  • ==Qualcomm 215 Mobile Platform
  • ==WSA8845H
  • ==WSA8830
  • ==AR8031
  • ==SM7550P
  • ==QCS4290
  • ==AR8035
  • ==WCD9370
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==SRV1H
  • ==Snapdragon X55 5G Modem-RF System
  • ==LeMans_AU_LGIT
  • ==QFW7114
  • ==SA6155P
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==FastConnect 6900
  • ==QCA6564A
  • ==QCA6564AU
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==QCN6224
  • ==Snapdragon 680 4G Mobile Platform
  • ==WCD9380
  • ==QAM8255P
  • ==QRB5165N
  • ==WCN3910
  • ==Snapdragon 888 5G Mobile Platform
  • ==SA6150P
  • ==SA8145P
  • ==WCN3615
  • ==CSRA6640
  • ==WCD9390
  • ==QCA6595AU
  • ==Snapdragon 460 Mobile Platform
  • ==SA6145P
  • ==QCA6595
  • ==SA7775P
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon X35 5G Modem-RF System
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==FastConnect 7800
  • ==QCM6490
  • ==FastConnect 6200
  • ==Snapdragon Auto 5G Modem-RF
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==FastConnect 6700
  • ==SA8195P
  • ==SW5100
  • ==SDA660
  • ==WSA8835
  • ==QCA6584AU
  • ==SM7325P
  • ==SM8635
  • ==Snapdragon XR2 5G Platform
  • ==G1 Gen 1
  • ==WCD9378
  • ==SA8150P
  • ==WCD9341
  • ==SM8550P
  • ==WCD9326
  • ==WCD9371
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==SD865 5G
  • ==WCN3950
  • ==CSRA6620
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==Snapdragon 685 4G Mobile Platform
  • ==WCN3680B
  • ==Snapdragon 480 5G Mobile Platform
  • ==SRV1M
  • ==MDM9250
  • ==SD662
  • ==QCA6174A
  • ==Flight RB5 5G Platform
  • ==QCA8081
  • ==SA8620P
  • ==Snapdragon 660 Mobile Platform
  • ==QCM5430
  • ==SM6650P
  • ==SA8155P
  • ==Snapdragon X53 5G Modem-RF System
  • ==QCM6125
  • ==QEP8111
  • ==QCA6797AQ
  • ==Milos
  • ==Snapdragon X72 5G Modem-RF System
  • ==QCA6574AU
  • ==QCA6698AU
  • ==WSA8815
  • ==SA8255P
  • ==SM7550
  • ==QAMSRV1M
  • ==QCA6688AQ
  • ==QCM4325
  • ==SA4155P
  • ==WCN6650
  • ==Snapdragon 778G 5G Mobile Platform
  • ==WCN3660B
  • ==Smart Audio 400 Platform
  • ==QFW7124
  • ==Robotics RB2 Platform
  • ==QCM2290
  • ==SA9000P
  • ==WCD9385
  • ==SM7675P
  • ==WCD9375
  • ==FWA Gen 3 Ultra Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==LeMansAU
  • ==QCA6698AQ
  • ==WCN6450
  • ==WCD9335
  • ==Snapdragon 782G Mobile Platform
  • ==QCA6696
  • ==SA4150P
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==MDM9628
  • ==QCN9012
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==QAMSRV1H
  • ==SA7255P
  • ==QCA6678AQ
  • ==SA8770P
  • ==WSA8810
  • ==Robotics RB5 Platform
  • ==QCA6574A
  • ==SM7675
  • ==SM7635P
  • ==QRB5165M
  • ==QCA2066
  • ==QCN6274
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==WCN3988
  • ==QAM8295P
  • ==Snapdragon X12 LTE Modem
  • ==SW5100P
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==WSA8845
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==QCC710
  • ==QCN9011
  • ==SM8650Q
  • ==WCD9395
  • ==QCA8337
  • ==QCS2290
  • ==WCN3990
  • ==QCA6574
  • ==Snapdragon X75 5G Modem-RF System
  • ==QCA6391
  • ==Snapdragon 870 5G Mobile Platform
  • ==WCN6755
  • ==Snapdragon 662 Mobile Platform
  • ==WSA8832
  • ==SA8295P
  • ==WCD9340
  • ==Snapdragon 865 5G Mobile Platform
  • ==FastConnect 6800
  • ==WCN3980
  • ==SM6225P

Matching in nixpkgs

Permalink CVE-2025-47376
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Use After Free in Automotive Audio

Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.

Affected products

Snapdragon
  • ==QCA8337
  • ==SDA660
  • ==QCM4325
  • ==WCD9340
  • ==QRB5165M
  • ==CSRA6640
  • ==WSA8845H
  • ==WCN3680B
  • ==AR8035
  • ==QCA6696
  • ==QCN6274
  • ==WCD9341
  • ==WCD9370
  • ==FastConnect 6900
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==FastConnect 6200
  • ==QCS4290
  • ==Snapdragon X35 5G Modem-RF System
  • ==Flight RB5 5G Platform
  • ==SM7675
  • ==QCA6595AU
  • ==QCA6574A
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==SW5100P
  • ==LeMansAU
  • ==WCD9371
  • ==Snapdragon X75 5G Modem-RF System
  • ==SM7550
  • ==SA8145P
  • ==QCA6698AQ
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==WCN3615
  • ==QCA9367
  • ==QCA6584AU
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8255P
  • ==SM7635P
  • ==Snapdragon 460 Mobile Platform
  • ==SM8550P
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WSA8810
  • ==Snapdragon X32 5G Modem-RF System
  • ==QCA9377
  • ==WSA8832
  • ==SM7675P
  • ==QCA6564AU
  • ==QCA6174A
  • ==FastConnect 7800
  • ==WCN3990
  • ==Snapdragon 660 Mobile Platform
  • ==QCM5430
  • ==MDM9250
  • ==LeMans_AU_LGIT
  • ==QCS2290
  • ==QFW7114
  • ==SRV1H
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==Snapdragon X53 5G Modem-RF System
  • ==Snapdragon 685 4G Mobile Platform
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==SA4155P
  • ==QCC710
  • ==FastConnect 6700
  • ==SD662
  • ==SM7550P
  • ==SM8635
  • ==WCN3980
  • ==Snapdragon 480 5G Mobile Platform
  • ==QCA6688AQ
  • ==SA9000P
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==SA7255P
  • ==Smart Audio 400 Platform
  • ==WCN6650
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==MDM9628
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8155P
  • ==QAM8295P
  • ==QCA6698AU
  • ==G1 Gen 1
  • ==QCN6224
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCN9012
  • ==SM8650Q
  • ==WCD9375
  • ==QFW7124
  • ==Snapdragon 870 5G Mobile Platform
  • ==SM7325P
  • ==QCS8550
  • ==WCD9378
  • ==WCN3988
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==QCA6797AQ
  • ==SA8620P
  • ==SM8635P
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==QCN9011
  • ==QAMSRV1H
  • ==SM6650P
  • ==SM6225P
  • ==WCD9385
  • ==WSA8840
  • ==QCM6125
  • ==WCN3950
  • ==SA8770P
  • ==WCD9390
  • ==WCD9335
  • ==QCA6564A
  • ==FWA Gen 3 Ultra Platform
  • ==WSA8845
  • ==FastConnect 6800
  • ==SW5100
  • ==QCA6595
  • ==WSA8815
  • ==Snapdragon X12 LTE Modem
  • ==Snapdragon 888 5G Mobile Platform
  • ==Robotics RB5 Platform
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon 778G 5G Mobile Platform
  • ==SA8195P
  • ==SA6145P
  • ==SA4150P
  • ==SA6155P
  • ==Snapdragon X55 5G Modem-RF System
  • ==SA7775P
  • ==WCN3660B
  • ==Snapdragon XR2 5G Platform
  • ==WCD9380
  • ==QCM2290
  • ==QAM8255P
  • ==SRV1M
  • ==Snapdragon 662 Mobile Platform
  • ==Snapdragon 865 5G Mobile Platform
  • ==SA8295P
  • ==SA6150P
  • ==SD865 5G
  • ==QCA6391
  • ==QCM6490
  • ==Snapdragon 690 5G Mobile Platform
  • ==AR8031
  • ==QCA6574AU
  • ==WCD9326
  • ==WCN3910
  • ==WCN6755
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==QCA6678AQ
  • ==QRB5165N
  • ==Snapdragon Auto 5G Modem-RF
  • ==Snapdragon 680 4G Mobile Platform
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==WSA8835
  • ==QCA6574
  • ==QCA8695AU
  • ==QEP8111
  • ==WSA8830
  • ==QCA8081
  • ==WCD9395
  • ==Qualcomm 215 Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==QAMSRV1M
  • ==SA8150P
  • ==Milos
  • ==Snapdragon X72 5G Modem-RF System
  • ==QCA2066
  • ==Robotics RB2 Platform
  • ==WCN6450
  • ==CSRA6620
  • ==Snapdragon 782G Mobile Platform
  • ==Snapdragon 888+ 5G Mobile Platform

Matching in nixpkgs

Permalink CVE-2025-47373
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Out-of-bounds Write in Automotive

Memory Corruption when accessing buffers with invalid length during TA invocation.

Affected products

Snapdragon
  • ==QCA8337
  • ==G2 Gen 1
  • ==QCM4325
  • ==SXR2230P
  • ==QLN1086BD
  • ==Cologne
  • ==SXR2350P
  • ==WCD9340
  • ==WCN7880
  • ==AR8035
  • ==WSA8845H
  • ==QRU1032
  • ==QCA6696
  • ==QCN6274
  • ==WCD9370
  • ==QXM1094
  • ==SC8380XP
  • ==SW6100
  • ==FastConnect 6900
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==FastConnect 6200
  • ==QCS4290
  • ==QDX1010
  • ==Snapdragon X35 5G Modem-RF System
  • ==SM7675
  • ==QCA6595AU
  • ==QXM1086
  • ==QCA6574A
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==QXM1093
  • ==Qualcomm Dragonwing X100 Accelerator Card
  • ==LeMansAU
  • ==WCD9371
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==Snapdragon X75 5G Modem-RF System
  • ==SM7550
  • ==SA8145P
  • ==SD 8 Gen1 5G
  • ==SM8750P
  • ==Snapdragon AR1 Gen 1 Platform
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==QCA6698AQ
  • ==WCN7861
  • ==XG101002
  • ==QCA6584AU
  • ==SA8255P
  • ==SM7635P
  • ==Snapdragon 460 Mobile Platform
  • ==SM8550P
  • ==SM7435
  • ==Pandeiro
  • ==QLN1083BD
  • ==WSA8810
  • ==Snapdragon X32 5G Modem-RF System
  • ==WSA8832
  • ==SM7675P
  • ==QMP1000
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==QCA6174A
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==FastConnect 7800
  • ==WCN7881
  • ==QCM5430
  • ==LeMans_AU_LGIT
  • ==QFW7114
  • ==SRV1H
  • ==IQ9 Series Platform
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SAR2230P
  • ==X2000092
  • ==QDX1011
  • ==Snapdragon 8 Elite
  • ==QCC710
  • ==FastConnect 6700
  • ==SD662
  • ==SM7550P
  • ==SM8635
  • ==Snapdragon 480 5G Mobile Platform
  • ==QCA6688AQ
  • ==SA9000P
  • ==SM8475P
  • ==QXM1095
  • ==SA7255P
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==WCN6650
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==SA8155P
  • ==Netrani
  • ==QAM8295P
  • ==QCA6698AU
  • ==G1 Gen 1
  • ==QCN6224
  • ==Themisto
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCN9012
  • ==Qualcomm Dragonwing QRU100 Platform
  • ==SM8650Q
  • ==WCD9375
  • ==QFW7124
  • ==QXM1083
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==X2000086
  • ==QCS8550
  • ==WCN7860
  • ==WCD9378
  • ==WCN3988
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==QCA6797AQ
  • ==SA8620P
  • ==SAR1250P
  • ==SM8635P
  • ==QCN9011
  • ==QAMSRV1H
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==SM6650P
  • ==SM6225P
  • ==SAR1165P
  • ==WCD9385
  • ==WSA8840
  • ==SW6100P
  • ==QAM8620P
  • ==WCN3950
  • ==SA8770P
  • ==WCD9390
  • ==FWA Gen 3 Ultra Platform
  • ==SA8540P
  • ==WSA8845
  • ==X2000094
  • ==SAR2130P
  • ==QCS4490
  • ==QCA6595
  • ==XG101039
  • ==WSA8815
  • ==QXM1096
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==IQ6 Series Platform
  • ==SA6145P
  • ==SA8195P
  • ==SA6155P
  • ==SXR2330P
  • ==SA7775P
  • ==WCD9380
  • ==QAM8255P
  • ==SRV1M
  • ==Snapdragon 662 Mobile Platform
  • ==SA8295P
  • ==QCM4490
  • ==SA6150P
  • ==WCD9378C
  • ==IQ8 Series Platform
  • ==Orne
  • ==Monaco_IOT
  • ==QCA6391
  • ==XG101032
  • ==X2000090
  • ==QCM6490
  • ==QPA1086BD
  • ==QCA6574AU
  • ==WCN3910
  • ==WCN6755
  • ==X2000077
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==QCA6678AQ
  • ==Snapdragon 8 Elite Gen 5
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==Snapdragon 680 4G Mobile Platform
  • ==WSA8835
  • ==QCA6574
  • ==SRV1L
  • ==QPA1083BD
  • ==QCA8695AU
  • ==QEP8111
  • ==WSA8830
  • ==QCA0000
  • ==QCA8081
  • ==WCD9395
  • ==QAMSRV1M
  • ==SA8150P
  • ==Snapdragon 695 5G Mobile Platform
  • ==Milos
  • ==Palawan25
  • ==Snapdragon X72 5G Modem-RF System
  • ==WCN6450
  • ==SXR2250P

Matching in nixpkgs

Permalink CVE-2026-3336
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 1 month, 3 weeks ago Activity log
  • Created suggestion
PKCS7_verify Certificate Chain Validation Bypass in AWS-LC

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

Affected products

AWS-LC
  • <1.69.0

Matching in nixpkgs

pkgs.aws-lc

General-purpose cryptographic library maintained by the AWS Cryptography team for AWS and their customers

Package maintainers

Permalink CVE-2025-59600
7.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Buffer Over-read in Graphics

Memory Corruption when adding user-supplied data without checking available buffer space.

Affected products

Snapdragon
  • ==QCA8337
  • ==G2 Gen 1
  • ==QCM4325
  • ==SXR2230P
  • ==QLN1086BD
  • ==SXR2350P
  • ==WCN7880
  • ==CSRA6640
  • ==WSA8845H
  • ==AR8035
  • ==QCA6696
  • ==SDX61
  • ==WCD9370
  • ==QXM1094
  • ==SC8380XP
  • ==SW6100
  • ==FastConnect 6900
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==QCS4290
  • ==FastConnect 6200
  • ==SM7675
  • ==QCA6595AU
  • ==QXM1086
  • ==QCA6574A
  • ==QXM1093
  • ==SW5100P
  • ==LeMansAU
  • ==SA8145P
  • ==SM8750P
  • ==Snapdragon AR1 Gen 1 Platform
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==Snapdragon X65 5G Modem-RF System
  • ==QCA6698AQ
  • ==QCN9024
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==WCN7861
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8255P
  • ==SM7635P
  • ==Snapdragon 460 Mobile Platform
  • ==SM7435
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==Pandeiro
  • ==QLN1083BD
  • ==WSA8810
  • ==WSA8832
  • ==SM7675P
  • ==QMP1000
  • ==QCA6564AU
  • ==QCA6174A
  • ==FastConnect 7800
  • ==WCN7881
  • ==QCM5430
  • ==LeMans_AU_LGIT
  • ==QCS2290
  • ==SRV1H
  • ==IQ9 Series Platform
  • ==QCN6024
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SAR2230P
  • ==Snapdragon 8 Elite
  • ==SA4155P
  • ==FastConnect 6700
  • ==SD662
  • ==SM8635
  • ==WCN3980
  • ==Snapdragon 480 5G Mobile Platform
  • ==QCA6688AQ
  • ==SA9000P
  • ==QXM1095
  • ==SA7255P
  • ==Smart Audio 400 Platform
  • ==Snapdragon 4 Gen 1 Mobile Platform
  • ==WCN6650
  • ==MDM9628
  • ==SA8155P
  • ==Netrani
  • ==G1 Gen 1
  • ==Themisto
  • ==QCN9012
  • ==SM8650Q
  • ==WCD9375
  • ==QXM1083
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==QCS8550
  • ==WCN7860
  • ==WCD9378
  • ==WCN3988
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==SA8620P
  • ==SAR1250P
  • ==SM8635P
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==QCN9011
  • ==QAMSRV1H
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==SM6650P
  • ==SM6225P
  • ==SAR1165P
  • ==WCD9385
  • ==WSA8840
  • ==SW6100P
  • ==QCM6125
  • ==WCN3950
  • ==SA8770P
  • ==WCD9390
  • ==WCD9335
  • ==QCA6564A
  • ==WSA8845
  • ==SAR2130P
  • ==QCS4490
  • ==QCA6595
  • ==SW5100
  • ==WSA8815
  • ==QXM1096
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==IQ6 Series Platform
  • ==SA6145P
  • ==SA8195P
  • ==SA4150P
  • ==SA6155P
  • ==SXR2330P
  • ==SA7775P
  • ==Snapdragon XR2 5G Platform
  • ==QCM2290
  • ==WCD9380
  • ==QAM8255P
  • ==SRV1M
  • ==Snapdragon 662 Mobile Platform
  • ==QCM4490
  • ==SA6150P
  • ==IQ8 Series Platform
  • ==SD865 5G
  • ==Orne
  • ==QCA6391
  • ==Monaco_IOT
  • ==QCM6490
  • ==QPA1086BD
  • ==AR8031
  • ==QCA6574AU
  • ==WCN3910
  • ==WCN6755
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==Snapdragon 8 Elite Gen 5
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==Snapdragon 680 4G Mobile Platform
  • ==WSA8835
  • ==QCA6574
  • ==QPA1083BD
  • ==WSA8830
  • ==QCA8081
  • ==WCD9395
  • ==QAMSRV1M
  • ==SA8150P
  • ==Snapdragon 695 5G Mobile Platform
  • ==Milos
  • ==Palawan25
  • ==QCA2066
  • ==WCN6450
  • ==CSRA6620
  • ==SXR2250P

Matching in nixpkgs

Permalink CVE-2026-3407
3.3 LOW
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month, 3 weeks ago Activity log
  • Created suggestion
YosysHQ yosys BLIF File rtlil.h set heap-based overflow

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Applying a patch is the recommended action to fix this issue. It appears that the issue is not reproducible all the time.

Affected products

yosys
  • ==0.11
  • ==0.26
  • ==0.37
  • ==0.18
  • ==0.22
  • ==0.42
  • ==0.61
  • ==0.21
  • ==0.25
  • ==0.29
  • ==0.57
  • ==0.35
  • ==0.8
  • ==0.24
  • ==0.58
  • ==0.47
  • ==0.39
  • ==0.7
  • ==0.34
  • ==0.27
  • ==0.41
  • ==0.60
  • ==0.1
  • ==0.45
  • ==0.13
  • ==0.49
  • ==0.31
  • ==0.59
  • ==0.30
  • ==0.14
  • ==0.36
  • ==0.52
  • ==0.10
  • ==0.4
  • ==0.40
  • ==0.50
  • ==0.51
  • ==0.56
  • ==0.12
  • ==0.33
  • ==0.20
  • ==0.54
  • ==0.16
  • ==0.46
  • ==0.9
  • ==0.55
  • ==0.17
  • ==0.38
  • ==0.3
  • ==0.32
  • ==0.62
  • ==0.23
  • ==0.53
  • ==0.44
  • ==0.43
  • ==0.6
  • ==0.5
  • ==0.28
  • ==0.2
  • ==0.15
  • ==0.48
  • ==0.19

Matching in nixpkgs

pkgs.yosys

Open RTL synthesis framework and tools

  • nixos-unstable 0.62
    • nixpkgs-unstable 0.62
    • nixos-unstable-small 0.62
  • nixos-25.11 0.55
    • nixos-25.11-small 0.55
    • nixpkgs-25.11-darwin 0.55

Package maintainers

Permalink CVE-2026-1628
4.6 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596

References

Affected products

Mattermost
  • ==5.13.4.0
  • =<5.13.3

Matching in nixpkgs

pkgs.mattermostLatest

Mattermost is an open source platform for secure collaboration across the entire software development lifecycle

Package maintainers

Permalink CVE-2025-47371
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): ADJACENT_NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 1 month, 3 weeks ago Activity log
  • Created suggestion
Reachable Assertion in Modem

Transient DOS when an LTE RLC packet with invalid TB is received by UE.

Affected products

Snapdragon
  • ==WSA8840
  • ==SM8635P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==WSA8845H
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==WSA8830
  • ==SM7550P
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==QCS4290
  • ==AR8035
  • ==QCN9024
  • ==WCD9370
  • ==Snapdragon X55 5G Modem-RF System
  • ==WCN7880
  • ==QFW7114
  • ==Snapdragon 7c Compute Platform
  • ==FastConnect 6900
  • ==SDX71M
  • ==QCN6224
  • ==WCD9360
  • ==Snapdragon 680 4G Mobile Platform
  • ==WCD9380
  • ==WCN3910
  • ==CSRA6640
  • ==WCD9390
  • ==QCA6595AU
  • ==Snapdragon 460 Mobile Platform
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==FastConnect 7800
  • ==Snapdragon Auto 5G Modem-RF
  • ==FastConnect 6200
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==FastConnect 6700
  • ==WSA8835
  • ==QCA6584AU
  • ==SM8635
  • ==SM8750P
  • ==G1 Gen 1
  • ==WCD9378
  • ==WCD9341
  • ==SM8550P
  • ==WCD9371
  • ==WCN7860
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==WCN3950
  • ==CSRA6620
  • ==Snapdragon 685 4G Mobile Platform
  • ==SD662
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==QCA6174A
  • ==SD 8 Gen1 5G
  • ==QCA8081
  • ==SM6650P
  • ==QCA6797AQ
  • ==QCM4490
  • ==Milos
  • ==Snapdragon X72 5G Modem-RF System
  • ==QCA6574AU
  • ==QCS8550
  • ==QCA6698AU
  • ==WSA8815
  • ==Netrani
  • ==QCN6024
  • ==SM7550
  • ==SM6250
  • ==5G Fixed Wireless Access Platform
  • ==QCA6688AQ
  • ==QCM4325
  • ==SM8475P
  • ==Orne
  • ==Snapdragon X65 5G Modem-RF System
  • ==WCN6650
  • ==QFW7124
  • ==Robotics RB2 Platform
  • ==QCM2290
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==WCD9385
  • ==SM7675P
  • ==QMP1000
  • ==WCD9375
  • ==FWA Gen 3 Ultra Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==QCA6698AQ
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==WCD9335
  • ==WCN7861
  • ==SDX61
  • ==QCA6696
  • ==QCN9012
  • ==WCN7881
  • ==SM7435
  • ==Snapdragon 8 Elite
  • ==QCA6678AQ
  • ==WSA8810
  • ==QCA6574A
  • ==SM7675
  • ==SM7635P
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==QCN6274
  • ==WCN3988
  • ==Palawan25
  • ==WSA8845
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==Snapdragon X80 5G Modem-RF System
  • ==QCC710
  • ==QCN9011
  • ==SM8650Q
  • ==WCD9395
  • ==QCA8337
  • ==QCS2290
  • ==Snapdragon X75 5G Modem-RF System
  • ==QCA6391
  • ==Snapdragon 870 5G Mobile Platform
  • ==WCN6755
  • ==Snapdragon 662 Mobile Platform
  • ==QCS4490
  • ==WSA8832
  • ==Snapdragon 7c Gen 2 Compute Platform "Rennell Pro"
  • ==WCD9340
  • ==Snapdragon 865 5G Mobile Platform
  • ==FastConnect 6800
  • ==SM6225P

Matching in nixpkgs

Permalink CVE-2026-23865
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 1 month, 3 weeks ago Activity log
  • Created suggestion
An integer overflow in the tt_var_load_item_variation_store function of the Freetype …

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

Affected products

FreeType
  • =<2.14.1
  • =<2.13.3

Matching in nixpkgs

Package maintainers