Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 4 months ago
Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.

Affected products

loupe
librsvg2
snapshot
gdk-pixbuf
  • <2.43.2
gdk-pixbuf2
glycin-loaders

Matching in nixpkgs

pkgs.loupe

Simple image viewer application written with GTK4 and Rust

  • nixos-unstable -

pkgs.snapshot

Take pictures and videos on your computer, tablet, or phone

  • nixos-unstable -

pkgs.rsnapshot

Filesystem snapshot utility for making backups of local and remote systems

  • nixos-unstable -

pkgs.aj-snapshot

Tool for storing/restoring JACK and/or ALSA connections to/from cml files

  • nixos-unstable -

pkgs.glycin-loaders

Glycin loaders for several formats

  • nixos-unstable -

pkgs.nix-snapshotter

Brings native understanding of Nix packages to containerd

  • nixos-unstable -

pkgs.btrfs-auto-snapshot

BTRFS Automatic Snapshot Service for Linux

  • nixos-unstable -

pkgs.zfs-prune-snapshots

Remove snapshots from one or more zpools that match given criteria

  • nixos-unstable -

pkgs.python312Packages.torchsnapshot

Performant, memory-efficient checkpointing library for PyTorch applications, designed with large, complex distributed workloads in mind

  • nixos-unstable -

pkgs.python313Packages.torchsnapshot

Performant, memory-efficient checkpointing library for PyTorch applications, designed with large, complex distributed workloads in mind

  • nixos-unstable -

pkgs.python312Packages.inline-snapshot

Create and update inline snapshots in Python tests

  • nixos-unstable -

pkgs.python312Packages.pytest-snapshot

Plugin to enable snapshot testing with pytest

  • nixos-unstable -

pkgs.python313Packages.inline-snapshot

Create and update inline snapshots in Python tests

  • nixos-unstable -

pkgs.python313Packages.pytest-snapshot

Plugin to enable snapshot testing with pytest

  • nixos-unstable -

pkgs.python312Packages.snapshot-restore-py

Snapshot Restore for Python library which can be used for registering runtime hooks in Snapstart enabled Python Lambda functions

  • nixos-unstable -

pkgs.python313Packages.snapshot-restore-py

Snapshot Restore for Python library which can be used for registering runtime hooks in Snapstart enabled Python Lambda functions

  • nixos-unstable -

pkgs.python312Packages.pytest-textual-snapshot

Snapshot testing for Textual applications

  • nixos-unstable -

pkgs.python313Packages.pytest-textual-snapshot

Snapshot testing for Textual applications

  • nixos-unstable -
created 4 months ago
Libgepub: integer overflow in libgepub's epub archive handling

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service.

Affected products

libgepub
  • <0.7.2

Matching in nixpkgs

pkgs.libgepub

GObject based library for handling and rendering epub documents

  • nixos-unstable -

Package maintainers: 4

created 4 months ago
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extension

A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocate.

Affected products

tigervnc
  • *
xwayland
  • <24.1.7
xorg-x11-server
  • *
xorg-x11-server-Xwayland
  • *

Matching in nixpkgs

pkgs.tigervnc

Fork of tightVNC, made in cooperation with VirtualGL

  • nixos-unstable -
created 4 months ago
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: unprocessed client request due to bytes to ignore

A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial of service.

Affected products

tigervnc
  • *
xwayland
  • <24.1.7
xorg-x11-server
  • *
xorg-x11-server-Xwayland
  • *

Matching in nixpkgs

pkgs.tigervnc

Fork of tightVNC, made in cooperation with VirtualGL

  • nixos-unstable -
created 4 months ago
Freeipa: idm: privilege escalation from host to domain admin in freeipa

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

Affected products

ipa
  • *
freeipa
  • <4.12.4
idm:DL1
  • *
idm:client
  • *

Matching in nixpkgs

pkgs.ipam

Cli based IPAM written in Go with PowerDNS support

pkgs.tipa

Phonetic font for TeX

  • nixos-unstable -

pkgs.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.freeipa

Identity, Policy and Audit system

  • nixos-unstable -

pkgs.ipafont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.ipatool

Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store

  • nixos-unstable -

pkgs.codipack

Fast gradient evaluation in C++ based on Expression Templates

  • nixos-unstable -

pkgs.snipaste

Screenshot tools

  • nixos-unstable -

pkgs.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.iniparser

Free standalone ini file parsing library

  • nixos-unstable -

pkgs.ipaexfont

Japanese font package with Mincho and Gothic fonts

  • nixos-unstable -

pkgs.multipass

Ubuntu VMs on demand for any workstation

  • nixos-unstable -

pkgs.nipap-cli

Neat IP Address Planner CLI

  • nixos-unstable -

pkgs.nipap-www

Neat IP Address Planner CLI, web UI

  • nixos-unstable -

pkgs.uriparser

Strictly RFC 3986 compliant URI parsing library

  • nixos-unstable -

pkgs.frangipanni

Convert lines of text into a tree structure

  • nixos-unstable -

pkgs.ipad_charge

Apple device USB charging utility for Linux

pkgs.nucleiparser

Nuclei output parser for CLI

  • nixos-unstable -

pkgs.multipath-tools

Tools for the Linux multipathing storage driver

  • nixos-unstable -

pkgs.ripasso-cursive

Simple password manager written in Rust

  • nixos-unstable -

pkgs.multipart-parser-c

Http multipart parser implemented in C

pkgs.haskellPackages.ipa

Internal Phonetic Alphabet (IPA)

pkgs.python312Packages.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.python313Packages.nipap

Neat IP Address Planner

  • nixos-unstable -

pkgs.python312Packages.ipaddr

IP address manipulation library

  • nixos-unstable -

pkgs.python312Packages.ipadic

Contemporary Written Japanese dictionary

  • nixos-unstable -

pkgs.python313Packages.ipaddr

IP address manipulation library

  • nixos-unstable -

pkgs.python313Packages.ipadic

Contemporary Written Japanese dictionary

  • nixos-unstable -

pkgs.haskellPackages.multipart

Parsers for the HTTP multipart format

  • nixos-unstable -

pkgs.python312Packages.pynipap

Python client library for Neat IP Address Planner

  • nixos-unstable -

pkgs.python313Packages.pynipap

Python client library for Neat IP Address Planner

  • nixos-unstable -

pkgs.python312Packages.iniparse

Accessing and Modifying INI files

  • nixos-unstable -

pkgs.python313Packages.iniparse

Accessing and Modifying INI files

  • nixos-unstable -

pkgs.graylogPlugins.ipanonymizer

Graylog-server plugin that replaces the last octet of IP addresses in messages with xxx

  • nixos-unstable -

pkgs.haskellPackages.unipatterns

Helpers which allow safe partial pattern matching in lambdas

pkgs.python312Packages.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.python312Packages.multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.python313Packages.gruut-ipa

Library for manipulating pronunciations using the International Phonetic Alphabet (IPA)

  • nixos-unstable -

pkgs.python313Packages.multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_1_0_0

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_1_1_0

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_1_1_1

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.typstPackages.ascii-ipa_2_0_0

Converter for ASCII representations of the International Phonetic Alphabet (IPA

  • nixos-unstable -

pkgs.haskellPackages.multipart-names

Handling of multipart names in various casing styles

  • nixos-unstable -

pkgs.haskellPackages.servant-multipart

multipart/form-data (e.g file upload) support for servant

  • nixos-unstable -

pkgs.python312Packages.flask-principal

Identity management for flask

  • nixos-unstable -

pkgs.python312Packages.types-ipaddress

Typing stubs for ipaddress

  • nixos-unstable -

pkgs.python313Packages.flask-principal

Identity management for flask

  • nixos-unstable -

pkgs.python313Packages.types-ipaddress

Typing stubs for ipaddress

  • nixos-unstable -

pkgs.python312Packages.cached-ipaddress

Cache construction of ipaddress objects

  • nixos-unstable -

pkgs.python312Packages.python-multipart

Streaming multipart parser for Python

  • nixos-unstable -

pkgs.python312Packages.python-vipaccess

Free software implementation of Symantec's VIP Access application and protocol

  • nixos-unstable -

pkgs.python312Packages.sansio-multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.python313Packages.cached-ipaddress

Cache construction of ipaddress objects

  • nixos-unstable -

pkgs.python313Packages.python-multipart

Streaming multipart parser for Python

  • nixos-unstable -

pkgs.python313Packages.python-vipaccess

Free software implementation of Symantec's VIP Access application and protocol

  • nixos-unstable -

pkgs.python313Packages.sansio-multipart

Parser for multipart/form-data

  • nixos-unstable -

pkgs.haskellPackages.http-client-multipart

Generate multipart uploads for http-client. (deprecated)

pkgs.haskellPackages.servant-multipart-api

multipart/form-data (e.g file upload) support for servant

  • nixos-unstable -

pkgs.haskellPackages.servant-multipart-client

multipart/form-data (e.g file upload) support for servant

  • nixos-unstable -

pkgs.python312Packages.nested-multipart-parser

Parser for nested data for 'multipart/form'

  • nixos-unstable -

pkgs.python313Packages.nested-multipart-parser

Parser for nested data for 'multipart/form'

  • nixos-unstable -

pkgs.haskellPackages.amazonka-connectparticipant

Amazon Connect Participant Service SDK

  • nixos-unstable -

pkgs.haskellPackages.autodocodec-servant-multipart

Autodocodec interpreters for Servant Multipart

pkgs.chickenPackages_5.chickenEggs.multipart-form-data

Reads & decodes HTTP multipart/form-data requests.

  • nixos-unstable -

pkgs.python312Packages.types-aiobotocore-connectparticipant

Type annotations for aiobotocore connectparticipant

  • nixos-unstable -

pkgs.python313Packages.types-aiobotocore-connectparticipant

Type annotations for aiobotocore connectparticipant

  • nixos-unstable -

pkgs.python312Packages.microsoft-kiota-serialization-multipart

Multipart serialization implementation for Kiota clients in Python

  • nixos-unstable -

pkgs.python313Packages.microsoft-kiota-serialization-multipart

Multipart serialization implementation for Kiota clients in Python

  • nixos-unstable -

Package maintainers: 24

created 4 months ago
Linux-pam: linux-pam directory traversal

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

Affected products

pam
  • *
linux-pam
  • <1.7.1
rhosdt/tempo-rhel8
  • *
rhosdt/tempo-query-rhel8
  • *
rhosdt/tempo-gateway-rhel8
  • *
rhosdt/tempo-rhel8-operator
  • *
rhpam-7/rhpam-rhel8-operator
  • *
rhpam-7/rhpam-kieserver-rhel8
  • *
rhpam-7/rhpam-operator-bundle
  • *
rhosdt/tempo-gateway-opa-rhel8
  • *
rhpam-7/rhpam-controller-rhel8
  • *
rhosdt/tempo-jaeger-query-rhel8
  • *
rhpam-7/rhpam-dashbuilder-rhel8
  • *
rhpam-7/rhpam-smartrouter-rhel8
  • *
discovery/discovery-server-rhel9
  • *
rhosdt/opentelemetry-rhel8-operator
  • *
rhpam-7/rhpam-businesscentral-rhel8
  • *
rhosdt/opentelemetry-collector-rhel8
  • *
registry.redhat.io/rhosdt/tempo-rhel8
  • *
rhpam-7/rhpam-process-migration-rhel8
  • *
web-terminal/web-terminal-tooling-rhel9
  • *
cert-manager/jetstack-cert-manager-rhel9
  • *
web-terminal/web-terminal-rhel9-operator
  • *
registry.redhat.io/rhosdt/tempo-query-rhel8
  • *
rhosdt/opentelemetry-target-allocator-rhel8
  • *
insights-proxy/insights-proxy-container-rhel9
  • *
registry.redhat.io/rhosdt/tempo-gateway-rhel8
  • *
compliance/openshift-compliance-openscap-rhel8
  • *
registry.redhat.io/rhosdt/tempo-rhel8-operator
  • *
rhpam-7/rhpam-businesscentral-monitoring-rhel8
  • *
openshift-sandboxed-containers/osc-monitor-rhel9
  • *
registry.redhat.io/rhosdt/tempo-gateway-opa-rhel8
  • *
registry.redhat.io/rhosdt/tempo-jaeger-query-rhel8
  • *
registry.redhat.io/discovery/discovery-server-rhel9
  • *
openshift-sandboxed-containers/osc-podvm-builder-rhel9
  • *
openshift-sandboxed-containers/osc-podvm-payload-rhel9
  • *
registry.redhat.io/rhosdt/opentelemetry-rhel8-operator
  • *
registry.redhat.io/rhosdt/opentelemetry-collector-rhel8
  • *
openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9
  • *
registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel8
  • *
registry.redhat.io/openshift-sandboxed-containers/osc-monitor-rhel9
  • *
registry.redhat.io/openshift-sandboxed-containers/osc-podvm-builder-rhel9
  • *
registry.redhat.io/openshift-sandboxed-containers/osc-podvm-payload-rhel9
  • *
registry.redhat.io/openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9
  • *

Matching in nixpkgs

pkgs.pam

Pluggable Authentication Modules, a flexible mechanism for authenticating user

  • nixos-unstable -

pkgs.ipam

Cli based IPAM written in Go with PowerDNS support

pkgs.opam

Package manager for OCaml

  • nixos-unstable -

pkgs.paml

Phylogenetic Analysis by Maximum Likelihood (PAML)

  • nixos-unstable -

pkgs.dspam

Community Driven Antispam Filter

  • nixos-unstable -

pkgs.pamix

Pulseaudio terminal mixer

  • nixos-unstable -

pkgs.rspamd

Advanced spam filtering system

  • nixos-unstable -

pkgs.openpam

Open source PAM library that focuses on simplicity, correctness, and cleanliness

pkgs.pam_p11

Authentication with PKCS#11 modules

  • nixos-unstable -

pkgs.pam_u2f

PAM module for allowing authentication with a U2F device

  • nixos-unstable -

pkgs.pamixer

Pulseaudio command line mixer

  • nixos-unstable -

pkgs.dopamine

Audio player that keeps it simple

pkgs.pam_krb5

PAM module allowing PAM-aware applications to authenticate users by performing an AS exchange with a Kerberos KDC

pkgs.pam_rssh

PAM module for authenticating via ssh-agent, written in Rust

  • nixos-unstable -

pkgs.pam_ussh

PAM module to authenticate using SSH certificates

pkgs.linux-pam

Pluggable Authentication Modules, a flexible mechanism for authenticating user

  • nixos-unstable -

pkgs.ncpamixer

Terminal mixer for PulseAudio inspired by pavucontrol

  • nixos-unstable -

pkgs.opam2json

Convert opam file syntax to JSON

  • nixos-unstable -

pkgs.pam_dp9ik

dp9ik pam module

  • nixos-unstable -

pkgs.pam_gnupg

Unlock GnuPG keys on login

  • nixos-unstable -

pkgs.pam_mount

PAM module to mount volumes for a user session

  • nixos-unstable -

pkgs.pam_mysql

PAM authentication module against a MySQL database

pkgs.pam_pgsql

Support to authenticate against PostgreSQL for PAM-enabled appliations

pkgs.pamtester

Utility program to test the PAM facility

  • nixos-unstable -

pkgs.pam_ccreds

PAM module to locally authenticate using an enterprise identity when the network is unavailable

  • nixos-unstable -
    • nixpkgs-unstable 10

pkgs.pam_mktemp

PAM for login service to provide per-user private directories

  • nixos-unstable -

pkgs.pam_rundir

Provide user runtime directory on Linux systems

  • nixos-unstable -

pkgs.pam_tmpdir

PAM module for creating safe per-user temporary directories

  • nixos-unstable -

pkgs.yubico-pam

Yubico PAM module

  • nixos-unstable -

pkgs.pam-watchid

PAM plugin module that allows the Apple Watch to be used for authentication

pkgs.apparmor-pam

Mandatory access control system - PAM service

  • nixos-unstable -

pkgs.opam-publish

Tool to ease contributions to opam repositories

  • nixos-unstable -

pkgs.pam-reattach

Reattach to the user's GUI session on macOS during authentication (for Touch ID support in tmux)

  • nixos-unstable -

pkgs.spamassassin

Open-Source Spam Filter

  • nixos-unstable -

pkgs.nss_pam_ldapd

LDAP identity and authentication for NSS/PAM

  • nixos-unstable -

pkgs.libpam-wrapper

Wrapper for testing PAM modules

  • nixos-unstable -

pkgs.opam-installer

Handle (un)installation from opam install files

  • nixos-unstable -

pkgs.pam-honeycreds

PAM module that sends warnings when fake passwords are used

  • nixos-unstable -

pkgs.rspamd-trainer

Grabs messages from a spam mailbox via IMAP and feeds them to Rspamd for training

pkgs.pam_ssh_agent_auth

PAM module for authentication through the SSH agent

  • nixos-unstable -

pkgs.rubyPackages.rpam2

pkgs.decode-spam-headers

Script that helps you understand why your E-Mail ended up in Spam

pkgs.haskellPackages.pam

Haskell binding for C PAM API

pkgs.luaPackages.lua-pam

Lua module for PAM authentication

pkgs.google-authenticator

Two-step verification, with pam module

  • nixos-unstable -

pkgs.lua51Packages.lua-pam

Lua module for PAM authentication

pkgs.lua52Packages.lua-pam

Lua module for PAM authentication

pkgs.lua53Packages.lua-pam

Lua module for PAM authentication

pkgs.rubyPackages_3_1.rpam2

pkgs.rubyPackages_3_2.rpam2

pkgs.rubyPackages_3_3.rpam2

pkgs.rubyPackages_3_4.rpam2

pkgs.kdePackages.kwallet-pam

PAM Integration with KWallet - Unlock KWallet when you login

  • nixos-unstable -

pkgs.opensmtpd-filter-rspamd

OpenSMTPD filter integration for the Rspamd daemon

  • nixos-unstable -

pkgs.python312Packages.pamqp

RabbitMQ Focused AMQP low-level library

  • nixos-unstable -

pkgs.python313Packages.pamqp

RabbitMQ Focused AMQP low-level library

  • nixos-unstable -

pkgs.sbclPackages.cl-xmlspam

pkgs.python312Packages.pamela

PAM interface using ctypes

  • nixos-unstable -

pkgs.python313Packages.pamela

PAM interface using ctypes

  • nixos-unstable -

pkgs.stalwart-mail-spam-filter

Secure & modern all-in-one mail server Stalwart (spam-filter module)

  • nixos-unstable -

pkgs.python312Packages.pypamtest

Wrapper for testing PAM modules

  • nixos-unstable -

pkgs.python313Packages.pypamtest

Wrapper for testing PAM modules

  • nixos-unstable -

pkgs.python312Packages.python-pam

Python pam module

  • nixos-unstable -

pkgs.python313Packages.python-pam

Python pam module

  • nixos-unstable -

pkgs.wordpressPackages.plugins.antispam-bee

  • nixos-unstable -

pkgs.matrix-synapse-plugins.matrix-synapse-pam

PAM auth provider for the Synapse Matrix server

  • nixos-unstable -

pkgs.matrix-synapse-plugins.synapse-http-antispam

Synapse module that forwards spam checking to an HTTP server

  • nixos-unstable -

pkgs.matrix-synapse-plugins.matrix-synapse-mjolnir-antispam

AntiSpam / Banlist plugin to be used with mjolnir

  • nixos-unstable -

pkgs.vscode-extensions.fabiospampinato.vscode-open-in-github

VS Code extension to open the current project or file in github.com

  • nixos-unstable -

Package maintainers: 55

created 4 months ago
WordPress Maia <= 1.1.15 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Maia allows PHP Local File Inclusion. This issue affects Maia: from n/a through 1.1.15.

Affected products

maia
  • =<1.1.15

Matching in nixpkgs

pkgs.maia-icon-theme

Icons based on Breeze and Super Flat Remix

pkgs.papirus-maia-icon-theme

Manjaro variation of Papirus icon theme

Package maintainers: 2

created 4 months ago
Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode

A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.

Affected products

tigervnc
xwayland
  • <24.1.7
xorg-x11-server
  • *
xorg-x11-server-Xwayland
  • *

Matching in nixpkgs

pkgs.tigervnc

Fork of tightVNC, made in cooperation with VirtualGL

  • nixos-unstable -
created 4 months ago
Unbounded recursion in Python Protobuf

Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901

Affected products

protobuf
  • <4.25.8
  • <5.29.5
  • <6.31.1

Matching in nixpkgs

pkgs.protobufc

C bindings for Google's Protocol Buffers

  • nixos-unstable -

pkgs.go-protobuf

Go bindings for protocol buffer

  • nixos-unstable -

pkgs.protobuf_21

Google's data interchange format

  • nixos-unstable -

pkgs.protobuf_25

Google's data interchange format

  • nixos-unstable -

pkgs.protobuf_27

Google's data interchange format

  • nixos-unstable -

pkgs.protobuf_29

Google's data interchange format

  • nixos-unstable -

pkgs.protobuf_30

Google's data interchange format

  • nixos-unstable -

pkgs.protobuf_31

Google's data interchange format

  • nixos-unstable -

pkgs.protobuf_32

Google's data interchange format

  • nixos-unstable -

pkgs.mypy-protobuf

Generate mypy stub files from protobuf specs

  • nixos-unstable -

pkgs.haskellPackages.protobuf

Google Protocol Buffers via GHC.Generics

pkgs.luaPackages.lua-protobuf

protobuf data support for Lua

pkgs.php81Extensions.protobuf

Google's language-neutral, platform-neutral, extensible mechanism for serializing structured data

  • nixos-unstable -

pkgs.php82Extensions.protobuf

Google's language-neutral, platform-neutral, extensible mechanism for serializing structured data

  • nixos-unstable -

pkgs.php83Extensions.protobuf

Google's language-neutral, platform-neutral, extensible mechanism for serializing structured data

  • nixos-unstable -

pkgs.php84Extensions.protobuf

Google's language-neutral, platform-neutral, extensible mechanism for serializing structured data

  • nixos-unstable -

pkgs.akkuPackages.r6rs-protobuf

Protocol Buffers for R6RS Scheme

pkgs.lua51Packages.lua-protobuf

protobuf data support for Lua

pkgs.lua52Packages.lua-protobuf

protobuf data support for Lua

pkgs.lua53Packages.lua-protobuf

protobuf data support for Lua

pkgs.lua54Packages.lua-protobuf

protobuf data support for Lua

pkgs.python313Packages.protobuf

Protocol Buffers are Google's data interchange format

  • nixos-unstable -

pkgs.luajitPackages.lua-protobuf

protobuf data support for Lua

pkgs.python312Packages.protobuf4

Protocol Buffers are Google's data interchange format

  • nixos-unstable -

pkgs.python312Packages.protobuf5

Protocol Buffers are Google's data interchange format

  • nixos-unstable -

pkgs.python312Packages.protobuf6

Protocol Buffers are Google's data interchange format

  • nixos-unstable -

pkgs.python313Packages.protobuf4

Protocol Buffers are Google's data interchange format

  • nixos-unstable -

pkgs.python313Packages.protobuf5

Protocol Buffers are Google's data interchange format

  • nixos-unstable -

pkgs.python313Packages.protobuf6

Protocol Buffers are Google's data interchange format

  • nixos-unstable -

pkgs.haskellPackages.riak-protobuf

Haskell types for the Riak protocol buffer API

pkgs.haskellPackages.protobuf-simple

Simple Protocol Buffers library (proto2)

pkgs.python312Packages.mypy-protobuf

Generate mypy stub files from protobuf specs

  • nixos-unstable -

pkgs.python312Packages.pure-protobuf

Python implementation of Protocol Buffers with dataclass-based schemas

  • nixos-unstable -

pkgs.python313Packages.mypy-protobuf

Generate mypy stub files from protobuf specs

  • nixos-unstable -

pkgs.python313Packages.pure-protobuf

Python implementation of Protocol Buffers with dataclass-based schemas

  • nixos-unstable -

pkgs.haskellPackages.protobuf-builder

Slow protobuf implementation

pkgs.python312Packages.types-protobuf

Typing stubs for protobuf

pkgs.python313Packages.types-protobuf

Typing stubs for protobuf

pkgs.haskellPackages.language-protobuf

Language definition and parser for Protocol Buffers

  • nixos-unstable -

pkgs.python312Packages.uplink-protobuf

Protocol Buffers (Protobuf) support for Uplink

  • nixos-unstable -

pkgs.python313Packages.uplink-protobuf

Protocol Buffers (Protobuf) support for Uplink

  • nixos-unstable -

pkgs.python312Packages.protobuf3-to-dict

Teeny Python library for creating Python dicts from protocol buffers and the reverse

pkgs.python313Packages.protobuf3-to-dict

Teeny Python library for creating Python dicts from protocol buffers and the reverse

pkgs.chickenPackages_5.chickenEggs.protobuf

Protocol buffer serialization

  • nixos-unstable -

pkgs.haskellPackages.proto-lens-protobuf-types

Basic protocol buffer message types

pkgs.python312Packages.sigstore-protobuf-specs

Library for serializing and deserializing Sigstore messages

  • nixos-unstable -

pkgs.python313Packages.sigstore-protobuf-specs

Library for serializing and deserializing Sigstore messages

  • nixos-unstable -

Package maintainers: 16

created 4 months ago
Libxml: heap use after free (uaf) leads to denial of service (dos)

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.

Affected products

rhcos
  • *
libxml2
  • *
  • <2.15.0
web-terminal/web-terminal-tooling-rhel9
  • *
cert-manager/jetstack-cert-manager-rhel9
  • *
web-terminal/web-terminal-rhel9-operator
  • *
insights-proxy/insights-proxy-container-rhel9
  • *
compliance/openshift-file-integrity-rhel8-operator
  • *
registry.redhat.io/insights-proxy/insights-proxy-container-rhel9
  • *

Matching in nixpkgs

pkgs.libxml2

XML parsing library for C

  • nixos-unstable -

pkgs.libxml2_13

XML parsing library for C

  • nixos-unstable -

pkgs.libxml2Python

  • nixos-unstable -

pkgs.python312Packages.libxml2

XML parsing library for C

  • nixos-unstable -

pkgs.python313Packages.libxml2

XML parsing library for C

  • nixos-unstable -

pkgs.tests.pkg-config.defaultPkgConfigPackages."libxml-2.0"

Test whether libxml2-2.14.5 exposes pkg-config modules libxml-2.0

Package maintainers: 7