Nixpkgs security tracker

Try the new UI
Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0665
published 6 months ago
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • gst_all_1.gst-vaapi
    • gst_all_1.gstreamermm
    • ocamlPackages.gstreamer
    • ocamlPackages_latest.gstreamer
    • obs-studio-plugins.obs-gstreamer
    • libsForQt5.phonon-backend-gstreamer
    • plasma5Packages.phonon-backend-gstreamer
    • tests.pkg-config.defaultPkgConfigPackages."gstreamer-controller-1.0"
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability


GStreamer
  • ==1c6e163aa33962f5ee4a87d29319ccdd5cb67612
OSS Sec announcement: https://www.openwall.com/lists/oss-security/2026/03/16/2
NIXPKGS-2026-0662
published 6 months ago
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • gst_all_1.gst-vaapi
    • gst_all_1.gstreamermm
    • ocamlPackages.gstreamer
    • ocamlPackages_latest.gstreamer
    • obs-studio-plugins.obs-gstreamer
    • libsForQt5.phonon-backend-gstreamer
    • plasma5Packages.phonon-backend-gstreamer
    • tests.pkg-config.defaultPkgConfigPackages."gstreamer-controller-1.0"
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability


GStreamer
  • ==1c6e163aa33962f5ee4a87d29319ccdd5cb67612
OSS Sec announcement: https://www.openwall.com/lists/oss-security/2026/03/16/2
NIXPKGS-2026-0659
published 6 months ago
Permalink CVE-2026-32772
3.4 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

telnet in GNU inetutils through 2.7 allows servers to read …


inetutils
  • =<2.7
Upstream discussion: https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00038.html
OSS Sec thread: https://www.openwall.com/lists/oss-security/2026/03/13/1
NIXPKGS-2026-0661
published 6 months ago
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • gst_all_1.gst-vaapi
    • gst_all_1.gstreamermm
    • ocamlPackages.gstreamer
    • ocamlPackages_latest.gstreamer
    • obs-studio-plugins.obs-gstreamer
    • libsForQt5.phonon-backend-gstreamer
    • plasma5Packages.phonon-backend-gstreamer
    • tests.pkg-config.defaultPkgConfigPackages."gstreamer-controller-1.0"
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability


GStreamer
  • ==1c6e163aa33962f5ee4a87d29319ccdd5cb67612
OSS Sec announcement: https://www.openwall.com/lists/oss-security/2026/03/16/2
NIXPKGS-2026-0672
published 6 months ago
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.llm-tools-simpleeval
    • python313Packages.llm-tools-simpleeval
    • python314Packages.llm-tools-simpleeval
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

(SimpleEval) Objects (including modules) can leak dangerous modules through to direct access inside the sandbox.


simpleeval
  • ==< 1.0.5
Upstream advisory: https://github.com/danthedeckie/simpleeval/security/advisories/GHSA-44vg-5wv2-h2hg
NIXPKGS-2026-0670
published 6 months ago
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • gst_all_1.gst-vaapi
    • gst_all_1.gstreamermm
    • ocamlPackages.gstreamer
    • ocamlPackages_latest.gstreamer
    • obs-studio-plugins.obs-gstreamer
    • libsForQt5.phonon-backend-gstreamer
    • plasma5Packages.phonon-backend-gstreamer
    • tests.pkg-config.defaultPkgConfigPackages."gstreamer-controller-1.0"
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability


GStreamer
  • ==1c6e163aa33962f5ee4a87d29319ccdd5cb67612
OSS Sec announcement: https://www.openwall.com/lists/oss-security/2026/03/16/2
NIXPKGS-2026-0667
published 6 months ago
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • gst_all_1.gst-vaapi
    • gst_all_1.gstreamermm
    • ocamlPackages.gstreamer
    • ocamlPackages_latest.gstreamer
    • obs-studio-plugins.obs-gstreamer
    • libsForQt5.phonon-backend-gstreamer
    • plasma5Packages.phonon-backend-gstreamer
    • tests.pkg-config.defaultPkgConfigPackages."gstreamer-controller-1.0"
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability


GStreamer
  • ==1c6e163aa33962f5ee4a87d29319ccdd5cb67612
OSS Sec announcement: https://www.openwall.com/lists/oss-security/2026/03/16/2
NIXPKGS-2026-0664
published 6 months ago
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • gst_all_1.gst-vaapi
    • gst_all_1.gstreamermm
    • ocamlPackages.gstreamer
    • ocamlPackages_latest.gstreamer
    • obs-studio-plugins.obs-gstreamer
    • libsForQt5.phonon-backend-gstreamer
    • plasma5Packages.phonon-backend-gstreamer
    • tests.pkg-config.defaultPkgConfigPackages."gstreamer-controller-1.0"
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability


GStreamer
  • ==1c6e163aa33962f5ee4a87d29319ccdd5cb67612
OSS Sec announcement: https://www.openwall.com/lists/oss-security/2026/03/16/2
NIXPKGS-2026-0660
published 6 months ago
Permalink CVE-2026-32746
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write …


inetutils
  • =<2.7
Upstream patch: https://codeberg.org/inetutils/inetutils/commit/6864598a29b652a6b69a958f5cd1318aa2b258af
NIXPKGS-2026-0673
published 6 months ago
Permalink CVE-2026-4174
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Radare2 Mach-O File mach0.c walk_exports_trie resource consumption


Radare2
  • ==5.9.9
  • ==6.1.2
Upstream issue: https://github.com/radareorg/radare2/issues/25482
Upstream patch: https://github.com/radareorg/radare2/commit/4371ae84c99c46b48cb21badbbef06b30757aba0

Upstream disputes the security issue: https://github.com/radareorg/radare2/issues/25482#issuecomment-3989318217