CVE-2025-55251 created 14 hours ago HCL AION is affected by an Unrestricted File Upload vulnerability HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise. Affected products AION ==2 Matching in nixpkgs pkgs.python312Packages.aionut Asyncio Network UPS Tools nixos-unstable 4.3.4 nixpkgs-unstable 4.3.4 nixos-unstable-small 4.3.4 nixos-25.05 4.3.4 nixos-25.05-small 4.3.4 nixpkgs-25.05-darwin 4.3.4 pkgs.python313Packages.aionut Asyncio Network UPS Tools nixos-unstable 4.3.4 nixpkgs-unstable 4.3.4 nixos-unstable-small 4.3.4 nixos-25.05 4.3.4 nixos-25.05-small 4.3.4 nixpkgs-25.05-darwin 4.3.4 pkgs.python312Packages.aiontfy Async ntfy client library nixos-unstable 0.6.1 nixpkgs-unstable 0.6.1 nixos-unstable-small 0.6.1 nixos-25.05 0.5.1 nixos-25.05-small 0.5.1 nixpkgs-25.05-darwin 0.5.1 pkgs.python313Packages.aiontfy Async ntfy client library nixos-unstable 0.6.1 nixpkgs-unstable 0.6.1 nixos-unstable-small 0.6.1 nixos-25.05 0.5.1 nixos-25.05-small 0.5.1 nixpkgs-25.05-darwin 0.5.1 pkgs.python312Packages.aionotion Python library for Notion Home Monitoring nixos-unstable 2025.02.0 nixpkgs-unstable 2025.02.0 nixos-unstable-small 2025.02.0 nixos-25.05 2024.03.0 nixos-25.05-small 2024.03.0 nixpkgs-25.05-darwin 2024.03.0 pkgs.python313Packages.aionotion Python library for Notion Home Monitoring nixos-unstable 2025.02.0 nixpkgs-unstable 2025.02.0 nixos-unstable-small 2025.02.0 nixos-25.05 2024.03.0 nixos-25.05-small 2024.03.0 nixpkgs-25.05-darwin 2024.03.0 pkgs.python312Packages.aionanoleaf Python wrapper for the Nanoleaf API nixos-unstable 0.2.1 nixpkgs-unstable 0.2.1 nixos-unstable-small 0.2.1 nixos-25.05 0.2.1 nixos-25.05-small 0.2.1 nixpkgs-25.05-darwin 0.2.1 pkgs.python313Packages.aionanoleaf Python wrapper for the Nanoleaf API nixos-unstable 0.2.1 nixpkgs-unstable 0.2.1 nixos-unstable-small 0.2.1 nixos-25.05 0.2.1 nixos-25.05-small 0.2.1 nixpkgs-25.05-darwin 0.2.1 pkgs.python312Packages.electrum-aionostr Asyncio nostr client nixos-unstable 0.0.11 nixpkgs-unstable 0.0.11 nixos-unstable-small 0.0.11 pkgs.python313Packages.electrum-aionostr Asyncio nostr client nixos-unstable 0.0.11 nixpkgs-unstable 0.0.11 nixos-unstable-small 0.0.11 Package maintainers: 2 @fabaff Fabian Affolter <mail@fabian-affolter.ch> @dotlambda Robert Schütz <rschuetz17@gmail.com>
pkgs.python312Packages.aionut Asyncio Network UPS Tools nixos-unstable 4.3.4 nixpkgs-unstable 4.3.4 nixos-unstable-small 4.3.4 nixos-25.05 4.3.4 nixos-25.05-small 4.3.4 nixpkgs-25.05-darwin 4.3.4
pkgs.python313Packages.aionut Asyncio Network UPS Tools nixos-unstable 4.3.4 nixpkgs-unstable 4.3.4 nixos-unstable-small 4.3.4 nixos-25.05 4.3.4 nixos-25.05-small 4.3.4 nixpkgs-25.05-darwin 4.3.4
pkgs.python312Packages.aiontfy Async ntfy client library nixos-unstable 0.6.1 nixpkgs-unstable 0.6.1 nixos-unstable-small 0.6.1 nixos-25.05 0.5.1 nixos-25.05-small 0.5.1 nixpkgs-25.05-darwin 0.5.1
pkgs.python313Packages.aiontfy Async ntfy client library nixos-unstable 0.6.1 nixpkgs-unstable 0.6.1 nixos-unstable-small 0.6.1 nixos-25.05 0.5.1 nixos-25.05-small 0.5.1 nixpkgs-25.05-darwin 0.5.1
pkgs.python312Packages.aionotion Python library for Notion Home Monitoring nixos-unstable 2025.02.0 nixpkgs-unstable 2025.02.0 nixos-unstable-small 2025.02.0 nixos-25.05 2024.03.0 nixos-25.05-small 2024.03.0 nixpkgs-25.05-darwin 2024.03.0
pkgs.python313Packages.aionotion Python library for Notion Home Monitoring nixos-unstable 2025.02.0 nixpkgs-unstable 2025.02.0 nixos-unstable-small 2025.02.0 nixos-25.05 2024.03.0 nixos-25.05-small 2024.03.0 nixpkgs-25.05-darwin 2024.03.0
pkgs.python312Packages.aionanoleaf Python wrapper for the Nanoleaf API nixos-unstable 0.2.1 nixpkgs-unstable 0.2.1 nixos-unstable-small 0.2.1 nixos-25.05 0.2.1 nixos-25.05-small 0.2.1 nixpkgs-25.05-darwin 0.2.1
pkgs.python313Packages.aionanoleaf Python wrapper for the Nanoleaf API nixos-unstable 0.2.1 nixpkgs-unstable 0.2.1 nixos-unstable-small 0.2.1 nixos-25.05 0.2.1 nixos-25.05-small 0.2.1 nixpkgs-25.05-darwin 0.2.1
pkgs.python312Packages.electrum-aionostr Asyncio nostr client nixos-unstable 0.0.11 nixpkgs-unstable 0.0.11 nixos-unstable-small 0.0.11
pkgs.python313Packages.electrum-aionostr Asyncio nostr client nixos-unstable 0.0.11 nixpkgs-unstable 0.0.11 nixos-unstable-small 0.0.11
CVE-2025-15533 created 1 day, 14 hours ago raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageFontAtlas of the file src/rtext.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. This patch is called 5a3391fdce046bc5473e52afbd835dd2dc127146. Applying a patch is advised to resolve this issue. Affected products raylib ==909f040 Matching in nixpkgs pkgs.raylib Simple and easy-to-use library to enjoy videogames programming nixos-unstable 5.5 nixpkgs-unstable 5.5 nixos-unstable-small 5.5 nixos-25.05 5.5 nixos-25.05-small 5.5 nixpkgs-25.05-darwin 5.5 pkgs.raylib-games Collection of games made with raylib nixos-unstable 2022-10-24 nixpkgs-unstable 2022-10-24 nixos-unstable-small 2022-10-24 nixos-25.05 2022-10-24 nixos-25.05-small 2022-10-24 nixpkgs-25.05-darwin 2022-10-24 pkgs.ocamlPackages.raylib OCaml bindings for Raylib (5.0.0) nixos-unstable 1.4.0 nixpkgs-unstable 1.4.0 nixos-unstable-small 1.4.0 pkgs.haskellPackages.h-raylib Raylib bindings for Haskell nixos-unstable 5.5.3.1 nixpkgs-unstable 5.5.3.1 nixos-unstable-small 5.5.3.1 nixos-25.05 5.5.2.1 nixos-25.05-small 5.5.2.1 nixpkgs-25.05-darwin 5.5.2.1 pkgs.python312Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2 pkgs.python313Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2 Package maintainers: 4 @Sigmanificient Yohann Boniface <sigmanificient@gmail.com> @diniamo diniamo <diniamo53@gmail.com> @ehmry Emery Hemingway <ehmry@posteo.net> @r17x Rin <hi@rin.rocks>
pkgs.raylib Simple and easy-to-use library to enjoy videogames programming nixos-unstable 5.5 nixpkgs-unstable 5.5 nixos-unstable-small 5.5 nixos-25.05 5.5 nixos-25.05-small 5.5 nixpkgs-25.05-darwin 5.5
pkgs.raylib-games Collection of games made with raylib nixos-unstable 2022-10-24 nixpkgs-unstable 2022-10-24 nixos-unstable-small 2022-10-24 nixos-25.05 2022-10-24 nixos-25.05-small 2022-10-24 nixpkgs-25.05-darwin 2022-10-24
pkgs.ocamlPackages.raylib OCaml bindings for Raylib (5.0.0) nixos-unstable 1.4.0 nixpkgs-unstable 1.4.0 nixos-unstable-small 1.4.0
pkgs.haskellPackages.h-raylib Raylib bindings for Haskell nixos-unstable 5.5.3.1 nixpkgs-unstable 5.5.3.1 nixos-unstable-small 5.5.3.1 nixos-25.05 5.5.2.1 nixos-25.05-small 5.5.2.1 nixpkgs-25.05-darwin 5.5.2.1
pkgs.python312Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2
pkgs.python313Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2
CVE-2026-0863 created 1 day, 14 hours ago Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host. Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via the Code block by an authenticated user with basic permissions and can lead to a full n8n instance takeover on instances operating under "Internal" execution mode. If the instance is operating under the "External" execution mode (ex. n8n's official Docker image) - arbitrary code execution occurs inside a Sidecar container and not the main node, which significantly reduces the vulnerability impact. Affected products n8n <2.4.2 <1.123.14 <2.3.5 Matching in nixpkgs pkgs.n8n Free and source-available fair-code licensed workflow automation tool nixos-unstable 1.119.2 nixpkgs-unstable 1.119.2 nixos-unstable-small 1.119.2 nixos-25.05 1.91.3 nixos-25.05-small 1.91.3 nixpkgs-25.05-darwin 1.91.3 Package maintainers: 1 @gepbird Gutyina Gergő <gutyina.gergo.2@gmail.com>
pkgs.n8n Free and source-available fair-code licensed workflow automation tool nixos-unstable 1.119.2 nixpkgs-unstable 1.119.2 nixos-unstable-small 1.119.2 nixos-25.05 1.91.3 nixos-25.05-small 1.91.3 nixpkgs-25.05-darwin 1.91.3
CVE-2025-15538 created 1 day, 14 hours ago Open Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after free A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/code/AssetLib/LWO/LWOMaterial.cpp. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128. Affected products Assimp ==6.0.2 ==6.0.0 ==6.0.1 Matching in nixpkgs pkgs.assimp Library to import various 3D model formats nixos-unstable 6.0.2 nixpkgs-unstable 6.0.2 nixos-unstable-small 6.0.2 nixos-25.05 5.4.3 nixos-25.05-small 5.4.3 nixpkgs-25.05-darwin 5.4.3 Package maintainers: 1 @ehmry Emery Hemingway <ehmry@posteo.net>
pkgs.assimp Library to import various 3D model formats nixos-unstable 6.0.2 nixpkgs-unstable 6.0.2 nixos-unstable-small 6.0.2 nixos-25.05 5.4.3 nixos-25.05-small 5.4.3 nixpkgs-25.05-darwin 5.4.3
CVE-2025-15534 created 1 day, 14 hours ago raysan5 raylib rtext.c LoadFontData integer overflow A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of the file src/rtext.c. The manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The identifier of the patch is 5a3391fdce046bc5473e52afbd835dd2dc127146. It is suggested to install a patch to address this issue. Affected products raylib ==909f040 Matching in nixpkgs pkgs.raylib Simple and easy-to-use library to enjoy videogames programming nixos-unstable 5.5 nixpkgs-unstable 5.5 nixos-unstable-small 5.5 nixos-25.05 5.5 nixos-25.05-small 5.5 nixpkgs-25.05-darwin 5.5 pkgs.raylib-games Collection of games made with raylib nixos-unstable 2022-10-24 nixpkgs-unstable 2022-10-24 nixos-unstable-small 2022-10-24 nixos-25.05 2022-10-24 nixos-25.05-small 2022-10-24 nixpkgs-25.05-darwin 2022-10-24 pkgs.ocamlPackages.raylib OCaml bindings for Raylib (5.0.0) nixos-unstable 1.4.0 nixpkgs-unstable 1.4.0 nixos-unstable-small 1.4.0 pkgs.haskellPackages.h-raylib Raylib bindings for Haskell nixos-unstable 5.5.3.1 nixpkgs-unstable 5.5.3.1 nixos-unstable-small 5.5.3.1 nixos-25.05 5.5.2.1 nixos-25.05-small 5.5.2.1 nixpkgs-25.05-darwin 5.5.2.1 pkgs.python312Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2 pkgs.python313Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2 Package maintainers: 4 @Sigmanificient Yohann Boniface <sigmanificient@gmail.com> @diniamo diniamo <diniamo53@gmail.com> @ehmry Emery Hemingway <ehmry@posteo.net> @r17x Rin <hi@rin.rocks>
pkgs.raylib Simple and easy-to-use library to enjoy videogames programming nixos-unstable 5.5 nixpkgs-unstable 5.5 nixos-unstable-small 5.5 nixos-25.05 5.5 nixos-25.05-small 5.5 nixpkgs-25.05-darwin 5.5
pkgs.raylib-games Collection of games made with raylib nixos-unstable 2022-10-24 nixpkgs-unstable 2022-10-24 nixos-unstable-small 2022-10-24 nixos-25.05 2022-10-24 nixos-25.05-small 2022-10-24 nixpkgs-25.05-darwin 2022-10-24
pkgs.ocamlPackages.raylib OCaml bindings for Raylib (5.0.0) nixos-unstable 1.4.0 nixpkgs-unstable 1.4.0 nixos-unstable-small 1.4.0
pkgs.haskellPackages.h-raylib Raylib bindings for Haskell nixos-unstable 5.5.3.1 nixpkgs-unstable 5.5.3.1 nixos-unstable-small 5.5.3.1 nixos-25.05 5.5.2.1 nixos-25.05-small 5.5.2.1 nixpkgs-25.05-darwin 5.5.2.1
pkgs.python312Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2
pkgs.python313Packages.raylib-python-cffi Python CFFI bindings for Raylib nixos-unstable 5.5.0.3 nixpkgs-unstable 5.5.0.3 nixos-unstable-small 5.5.0.3 nixos-25.05 5.5.0.2 nixos-25.05-small 5.5.0.2 nixpkgs-25.05-darwin 5.5.0.2
CVE-2025-62230 created 1 month, 4 weeks ago Xorg: xwayland: use-after-free in xkb client resource removal A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. Affected products tigervnc * xwayland <24.1.9 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0
CVE-2025-62231 created 1 month, 4 weeks ago Xorg: xmayland: value overflow in xkbsetcompatmap() A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. Affected products tigervnc * xwayland <24.1.9 xorg-x11-server * xorg-x11-server-Xwayland * Matching in nixpkgs pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-unstable 1.15.0 nixpkgs-unstable 1.15.0 nixos-unstable-small 1.15.0 nixos-25.05 1.14.0 nixos-25.05-small 1.14.0 nixpkgs-25.05-darwin 1.14.0
CVE-2025-54941 created 1 month, 4 weeks ago Apache Airflow: Command injection in "example_dag_decorator" An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the example dag code copied to build your own similar dag. If you used the `example_dag_decorator` please review it and apply the changes implemented in Airflow 3.0.5 accordingly. Affected products apache-airflow << 3.0.5 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3 Package maintainers: 3 @ingenieroariel Ariel Nunez <ariel@nunez.co> @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixpkgs-unstable 2.7.3 nixos-unstable-small 2.7.3 nixos-25.05 2.7.3 nixos-25.05-small 2.7.3 nixpkgs-25.05-darwin 2.7.3
CVE-2025-9640 created 1 month, 4 weeks ago Samba: vfs_streams_xattr uninitialized memory write possible A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability. Affected products rhcos samba <4.23.2 <4.21.9 <4.21.5 samba4 Matching in nixpkgs pkgs.samba Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3 pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable 4.22.3 nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3 nixos-25.05 4.20.8 nixos-25.05-small 4.20.8 nixpkgs-25.05-darwin 4.20.8 pkgs.sambamba SAM/BAM processing tool nixos-unstable 1.0.1 nixpkgs-unstable 1.0.1 nixos-unstable-small 1.0.1 nixos-25.05 1.0.1 nixos-25.05-small 1.0.1 nixpkgs-25.05-darwin 1.0.1 pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable 4.22.3 nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3 nixos-25.05 4.20.8 nixos-25.05-small 4.20.8 nixpkgs-25.05-darwin 4.20.8 pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable 4.22.3 nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3 nixos-25.05 4.20.8 nixos-25.05-small 4.20.8 nixpkgs-25.05-darwin 4.20.8 Package maintainers: 2 @aneeshusa Aneesh Agrawal <aneeshusa@gmail.com> @jbedo Justin Bedő <cu@cua0.org>
pkgs.samba Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3
pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable 4.22.3 nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3 nixos-25.05 4.20.8 nixos-25.05-small 4.20.8 nixpkgs-25.05-darwin 4.20.8
pkgs.sambamba SAM/BAM processing tool nixos-unstable 1.0.1 nixpkgs-unstable 1.0.1 nixos-unstable-small 1.0.1 nixos-25.05 1.0.1 nixos-25.05-small 1.0.1 nixpkgs-25.05-darwin 1.0.1
pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable 4.22.3 nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3 nixos-25.05 4.20.8 nixos-25.05-small 4.20.8 nixpkgs-25.05-darwin 4.20.8
pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable 4.22.3 nixpkgs-unstable 4.22.3 nixos-unstable-small 4.22.3 nixos-25.05 4.20.8 nixos-25.05-small 4.20.8 nixpkgs-25.05-darwin 4.20.8
CVE-2025-53881 created 1 month, 4 weeks ago SUSE-specific logrotate configuration allows escalation from mail user/group to root A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1. Affected products exim <4.98.2-lp156.248.1 Matching in nixpkgs pkgs.exim Mail transfer agent (MTA) nixos-unstable 4.98.2 nixpkgs-unstable 4.98.2 nixos-unstable-small 4.98.2 nixos-25.05 4.98.2 nixos-25.05-small 4.98.2 nixpkgs-25.05-darwin 4.98.2 Package maintainers: 4 @Conni2461 Simon Hauser <simon-hauser@outlook.com> @dasJ Janne Heß <janne@hess.ooo> @4z3 Tomislav Viljetić <tv@krebsco.de> @helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de>
pkgs.exim Mail transfer agent (MTA) nixos-unstable 4.98.2 nixpkgs-unstable 4.98.2 nixos-unstable-small 4.98.2 nixos-25.05 4.98.2 nixos-25.05-small 4.98.2 nixpkgs-25.05-darwin 4.98.2