CVE-2025-5915 created 4 months ago Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions. Affected products rhcos libarchive <3.8.0 Matching in nixpkgs pkgs.libarchive Multi-format archive and compression library nixos-unstable - nixpkgs-unstable 3.8.1 pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable - nixpkgs-unstable 2.0.8 pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable - nixpkgs-unstable 3.0.4.2 pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable - nixpkgs-unstable 20.1.0 pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable - nixpkgs-unstable 5.3 pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable - nixpkgs-unstable 5.3 pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable - nixpkgs-unstable 1.0.0.1 pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable - nixpkgs-unstable 0.1.0.0 pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable - nixpkgs-unstable 21.5.31 pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable - nixpkgs-unstable 21.5.31 Package maintainers: 8 @aanderse Aaron Andersen <aaron@fosslib.net> @peterhoeg Peter Hoeg <peter@hoeg.com> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @minijackson Rémi Nicole <minijackson@riseup.net> @cpages Carles Pagès <page@ruiec.cat> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @jcumming Jack Cummings <jack@mudshark.org>
pkgs.libarchive-qt Qt based archiving solution with libarchive backend nixos-unstable - nixpkgs-unstable 2.0.8
pkgs.haskellPackages.libarchive Haskell interface to libarchive nixos-unstable - nixpkgs-unstable 3.0.4.2
pkgs.kodiPackages.vfs-libarchive LibArchive Virtual Filesystem add-on for Kodi nixos-unstable - nixpkgs-unstable 20.1.0
pkgs.python312Packages.libarchive-c Python interface to libarchive nixos-unstable - nixpkgs-unstable 5.3
pkgs.python313Packages.libarchive-c Python interface to libarchive nixos-unstable - nixpkgs-unstable 5.3
pkgs.haskellPackages.archive-libarchive Common interface using libarchive nixos-unstable - nixpkgs-unstable 1.0.0.1
pkgs.haskellPackages.libarchive-conduit Read many archive formats with libarchive and conduit nixos-unstable - nixpkgs-unstable 0.1.0.0
pkgs.python312Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable - nixpkgs-unstable 21.5.31
pkgs.python313Packages.extractcode-libarchive ScanCode Toolkit plugin to provide pre-built binary libraries and utilities and their locations nixos-unstable - nixpkgs-unstable 21.5.31
CVE-2025-47711 created 4 months ago Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service. Affected products nbdkit <1.40.6 <1.42.3 <1.38.6 virt:av/nbdkit virt:8.2/nbdkit virt:rhel/nbdkit Matching in nixpkgs pkgs.nbdkit NBD server with stable plugin ABI and permissive license nixos-unstable - nixpkgs-unstable 1.44.1 Package maintainers: 1 @lukts30 lukts30 <llukas21307@gmail.com>
pkgs.nbdkit NBD server with stable plugin ABI and permissive license nixos-unstable - nixpkgs-unstable 1.44.1
CVE-2025-0620 created 4 months ago Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again. Affected products rhcos samba <4.21.6 samba4 Matching in nixpkgs pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3 pkgs.sambamba SAM/BAM processing tool nixos-unstable - nixpkgs-unstable 1.0.1 pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3 pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3 Package maintainers: 2 @aneeshusa Aneesh Agrawal <aneeshusa@gmail.com> @jbedo Justin Bedő <cu@cua0.org>
pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3
pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3
pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable - nixpkgs-unstable 4.22.3
CVE-2025-49241 created 4 months ago WordPress oik <= 4.15.1 - Broken Access Control Vulnerability Missing Authorization vulnerability in bobbingwide oik allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects oik: from n/a through 4.15.1. Affected products oik =<4.15.1 Matching in nixpkgs pkgs.libvoikko Finnish language processing library nixos-unstable - nixpkgs-unstable 4.3.3 Package maintainers: 1 @Lurkki14 Jussi Kuokkanen <jussi.kuokkanen@protonmail.com>
CVE-2025-49075 created 4 months ago WordPress Wishlist plugin <= 1.0.43 - Cross Site Scripting (XSS) vulnerability Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist allows Stored XSS.This issue affects Wishlist: from n/a through 1.0.43. Affected products wishlist =<1.0.43 Matching in nixpkgs pkgs.wishlist Single entrypoint for multiple SSH endpoints nixos-unstable - nixpkgs-unstable 0.15.2 Package maintainers: 2 @caarlos0 Carlos A Becker <carlos@becker.software> @penguwin Nicolas Martin <penguwin@penguwin.eu>
CVE-2011-10007 created 4 months ago File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted file name File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a command to be executed. Example: $ mkdir /tmp/poc; echo > "/tmp/poc/|id" $ perl -MFile::Find::Rule \ -E 'File::Find::Rule->grep("foo")->in("/tmp/poc")' uid=1000(user) gid=1000(user) groups=1000(user),100(users) Affected products File-Find-Rule =<0.34 Matching in nixpkgs pkgs.perlPackages.FileFindRule File::Find::Rule is a friendlier interface to File::Find nixos-unstable - nixpkgs-unstable 0.34 pkgs.perl538Packages.FileFindRule File::Find::Rule is a friendlier interface to File::Find nixos-unstable - nixpkgs-unstable 0.34 pkgs.perl540Packages.FileFindRule File::Find::Rule is a friendlier interface to File::Find nixos-unstable - nixpkgs-unstable 0.34 pkgs.perlPackages.FileFindRulePerl Common rules for searching for Perl things nixos-unstable - nixpkgs-unstable 1.16 pkgs.perl538Packages.FileFindRulePerl Common rules for searching for Perl things nixos-unstable - nixpkgs-unstable 1.16 pkgs.perl540Packages.FileFindRulePerl Common rules for searching for Perl things nixos-unstable - nixpkgs-unstable 1.16
pkgs.perlPackages.FileFindRule File::Find::Rule is a friendlier interface to File::Find nixos-unstable - nixpkgs-unstable 0.34
pkgs.perl538Packages.FileFindRule File::Find::Rule is a friendlier interface to File::Find nixos-unstable - nixpkgs-unstable 0.34
pkgs.perl540Packages.FileFindRule File::Find::Rule is a friendlier interface to File::Find nixos-unstable - nixpkgs-unstable 0.34
pkgs.perlPackages.FileFindRulePerl Common rules for searching for Perl things nixos-unstable - nixpkgs-unstable 1.16
pkgs.perl538Packages.FileFindRulePerl Common rules for searching for Perl things nixos-unstable - nixpkgs-unstable 1.16
pkgs.perl540Packages.FileFindRulePerl Common rules for searching for Perl things nixos-unstable - nixpkgs-unstable 1.16
CVE-2025-40908 created 4 months ago YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified Affected products YAML-LibYAML <0.903.0 Matching in nixpkgs pkgs.perlPackages.YAMLLibYAML Perl YAML Serialization using XS and libyaml nixos-unstable - nixpkgs-unstable 0.89 pkgs.perl538Packages.YAMLLibYAML Perl YAML Serialization using XS and libyaml nixos-unstable - nixpkgs-unstable 0.89 pkgs.perl540Packages.YAMLLibYAML Perl YAML Serialization using XS and libyaml nixos-unstable - nixpkgs-unstable 0.89
pkgs.perlPackages.YAMLLibYAML Perl YAML Serialization using XS and libyaml nixos-unstable - nixpkgs-unstable 0.89
pkgs.perl538Packages.YAMLLibYAML Perl YAML Serialization using XS and libyaml nixos-unstable - nixpkgs-unstable 0.89
pkgs.perl540Packages.YAMLLibYAML Perl YAML Serialization using XS and libyaml nixos-unstable - nixpkgs-unstable 0.89
CVE-2024-12224 created 4 months ago idna accepts Punycode labels that do not produce any non-ASCII when decoded Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname. Affected products idna <1.0.0 Matching in nixpkgs pkgs.echidna Ethereum smart contract fuzzer nixos-unstable - nixpkgs-unstable 2.2.6 pkgs.unicode-idna Unicode IDNA compatible processing data nixos-unstable - nixpkgs-unstable 16.0.0 pkgs.kodiPackages.idna Internationalized Domain Names for Python nixos-unstable - nixpkgs-unstable 3.10.0 pkgs.sbclPackages.idna nixos-unstable - nixpkgs-unstable 20120107-git pkgs.python312Packages.idna Internationalized Domain Names in Applications (IDNA) nixos-unstable - nixpkgs-unstable 3.10 pkgs.python313Packages.idna Internationalized Domain Names in Applications (IDNA) nixos-unstable - nixpkgs-unstable 3.10 pkgs.python312Packages.idna-ssl Patch ssl.match_hostname for Unicode(idna) domains support nixos-unstable - nixpkgs-unstable 1.1.0 pkgs.python313Packages.idna-ssl Patch ssl.match_hostname for Unicode(idna) domains support nixos-unstable - nixpkgs-unstable 1.1.0 Package maintainers: 16 @hellwolf Miao, ZhiCheng <zhicheng.miao@gmail.com> @arcz Artur Cygan <arczicygan@gmail.com> @peterhoeg Peter Hoeg <peter@hoeg.com> @nvmd Sergey Kazenyuk <kazenyuk@pm.me> @cpages Carles Pagès <page@ruiec.cat> @edwtjo Edward Tjörnhammar <ed@cflags.cc> @minijackson Rémi Nicole <minijackson@riseup.net> @dschrempf Dominik Schrempf <dominik.schrempf@gmail.com> @aanderse Aaron Andersen <aaron@fosslib.net> @dotlambda Robert Schütz <rschuetz17@gmail.com> @7c6f434c Michael Raskin <7c6f434c@mail.ru> @lukego Luke Gorrie <luke@snabb.co> @Uthar Kasper Gałkowski <galkowskikasper@gmail.com> @nagy Daniel Nagy <danielnagy@posteo.de> @hraban Hraban Luyat <hraban@0brg.net> @jopejoe1 jopejoe1 <nixpkgs@missing.ninja>
pkgs.kodiPackages.idna Internationalized Domain Names for Python nixos-unstable - nixpkgs-unstable 3.10.0
pkgs.python312Packages.idna Internationalized Domain Names in Applications (IDNA) nixos-unstable - nixpkgs-unstable 3.10
pkgs.python313Packages.idna Internationalized Domain Names in Applications (IDNA) nixos-unstable - nixpkgs-unstable 3.10
pkgs.python312Packages.idna-ssl Patch ssl.match_hostname for Unicode(idna) domains support nixos-unstable - nixpkgs-unstable 1.1.0
pkgs.python313Packages.idna-ssl Patch ssl.match_hostname for Unicode(idna) domains support nixos-unstable - nixpkgs-unstable 1.1.0
CVE-2025-4598 created 4 months ago Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality. Affected products rhcos systemd * rpm-ostree NetworkManager systemd-coredump <255.19 <252.37 <257.6 <253.32 <256.14 <254.25 rhceph/rhceph-7-rhel9 * rhceph/rhceph-8-rhel9 * insights-proxy/insights-proxy-container-rhel9 * Matching in nixpkgs pkgs.udev System and service manager for Linux nixos-unstable - nixpkgs-unstable 257.8 pkgs.systemd System and service manager for Linux nixos-unstable - nixpkgs-unstable 257.8 pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable - nixpkgs-unstable 2024.8 pkgs.systemd-lsp Language server implementation for systemd unit files made in Rust nixos-unstable - nixpkgs-unstable 0.1.0 pkgs.systemdLibs System and service manager for Linux nixos-unstable - nixpkgs-unstable 257.8 pkgs.rofi-systemd Control your systemd units using rofi nixos-unstable - nixpkgs-unstable 0.1.1 pkgs.systemd-wait Wait for a systemd unit to enter a specific state nixos-unstable - nixpkgs-unstable 0.1+2018-10-05 pkgs.systemdUkify System and service manager for Linux nixos-unstable - nixpkgs-unstable 257.8 pkgs.systemdgenie Systemd management utility nixos-unstable - nixpkgs-unstable 0.99.0 pkgs.check_systemd Nagios / Icinga monitoring plugin to check systemd for failed units nixos-unstable - nixpkgs-unstable 5.0.0 pkgs.systemdMinimal System and service manager for Linux nixos-unstable - nixpkgs-unstable 257.8 pkgs.systemd-netlogd Forwards messages from the journal to other hosts over the network nixos-unstable - nixpkgs-unstable 1.4.4 pkgs.systemd-bootchart Boot performance graphing tool from systemd nixos-unstable - nixpkgs-unstable 235 pkgs.networkmanager-l2tp L2TP plugin for NetworkManager nixos-unstable - nixpkgs-unstable l2tp-gnome-1.20.20 pkgs.networkmanager-sstp NetworkManager's sstp plugin nixos-unstable - nixpkgs-unstable 1.3.2 pkgs.networkmanager-vpnc NetworkManager's VPNC plugin nixos-unstable - nixpkgs-unstable 1.4.0 pkgs.systemd-manager-tui Program for managing systemd services through a TUI nixos-unstable - nixpkgs-unstable 1.1.0 pkgs.systemd-lock-handler Translates systemd-system lock/sleep signals into systemd-user target activations nixos-unstable - nixpkgs-unstable 2.4.2 pkgs.networkmanager-iodine NetworkManager's iodine plugin nixos-unstable - nixpkgs-unstable 1.2.0-unstable-2025-09-06 pkgs.networkmanager-openvpn NetworkManager's OpenVPN plugin nixos-unstable - nixpkgs-unstable 1.12.3 pkgs.haskellPackages.systemd Systemd facilities (Socket activation, Notify) nixos-unstable - nixpkgs-unstable 2.4.0 pkgs.php81Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11 pkgs.php82Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11 pkgs.php83Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11 pkgs.php84Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11 pkgs.systemd-language-server Language Server for Systemd unit files nixos-unstable - nixpkgs-unstable 0.3.5 pkgs.update-systemd-resolved Helper script for OpenVPN to directly update the DNS settings of a link through systemd-resolved via DBus nixos-unstable - nixpkgs-unstable 1.3.0 pkgs.networkmanager_strongswan NetworkManager's strongswan plugin nixos-unstable - nixpkgs-unstable 1.6.2 pkgs.python312Packages.systemd Python module for native access to the systemd facilities nixos-unstable - nixpkgs-unstable 235 pkgs.python313Packages.systemd Python module for native access to the systemd facilities nixos-unstable - nixpkgs-unstable 235 pkgs.networkmanager-fortisslvpn NetworkManager’s FortiSSL plugin nixos-unstable - nixpkgs-unstable 1.4.0 pkgs.networkmanager-openconnect NetworkManager’s OpenConnect plugin nixos-unstable - nixpkgs-unstable 1.2.10 pkgs.haskellPackages.systemd-api systemd bindings nixos-unstable - nixpkgs-unstable 0.1.0.1 pkgs.nagiosPlugins.check_systemd Nagios / Icinga monitoring plugin to check systemd for failed units nixos-unstable - nixpkgs-unstable 5.0.0 pkgs.prometheus-systemd-exporter Exporter for systemd unit metrics nixos-unstable - nixpkgs-unstable 0.7.0 pkgs.haskellPackages.warp-systemd Socket activation and other systemd integration for the Warp web server (WAI) nixos-unstable - nixpkgs-unstable 0.3.0.0 pkgs.gnomeExtensions.systemd-status Show systemd system state nixos-unstable - nixpkgs-unstable 8 pkgs.gnomeExtensions.systemd-manager GNOME Shell extension to manage systemd services nixos-unstable - nixpkgs-unstable 19 pkgs.haskellPackages.libsystemd-journal Haskell bindings to libsystemd-journal nixos-unstable - nixpkgs-unstable 1.4.6.0 pkgs.python312Packages.systemdunitparser SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files nixos-unstable - nixpkgs-unstable 0.4 pkgs.python313Packages.systemdunitparser SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files nixos-unstable - nixpkgs-unstable 0.4 pkgs.python312Packages.jupyterhub-systemdspawner JupyterHub Spawner using systemd for resource isolation nixos-unstable - nixpkgs-unstable 1.0.2 pkgs.python313Packages.jupyterhub-systemdspawner JupyterHub Spawner using systemd for resource isolation nixos-unstable - nixpkgs-unstable 1.0.2 pkgs.vscode-extensions.coolbear.systemd-unit-file nixos-unstable - nixpkgs-unstable 1.0.6 pkgs.gnomeExtensions.systemd-offline-update-indicator Show an indicator for pending systemd offline updates. nixos-unstable - nixpkgs-unstable 7 pkgs.tests.pkg-config.defaultPkgConfigPackages.libudev Test whether systemd-257.8 exposes pkg-config modules libudev nixos-unstable - nixpkgs-unstable pkgs.tests.pkg-config.defaultPkgConfigPackages.libsystemd Test whether systemd-257.8 exposes pkg-config modules libsystemd nixos-unstable - nixpkgs-unstable Package maintainers: 30 @symphorien Guillaume Girol <symphorien_nixpkgs@xlumurb.eu> @doronbehar Doron Behar <me@doronbehar.com> @linsui linsui <linsui555@gmail.com> @honnip Jung seungwoo <me@honnip.page> @sternenseemann Lukas Epple <sternenseemann@systemli.org> @mpscholten Marc Scholten <marc@digitallyinduced.com> @obadz obadz <obadz-nixos@obadz.com> @jtojnar Jan Tojnar <jtojnar@gmail.com> @talyz Kim Lindberger <kim.lindberger@gmail.com> @aanderse Aaron Andersen <aaron@fosslib.net> @Ma27 Maximilian Bosch <maximilian@mbosch.me> @piotrkwiecinski Piotr Kwiecinski <piokwiecinski+nixpkgs@gmail.com> @chkno Scott Worley <scottworley@scottworley.com> @RaitoBezarius Ryan Lahfa <ryan@lahfa.xyz> @malikwirin Malik <abdelmalik.najhi@stud.hs-kempten.de> @colonelpanic8 Ivan Malison <IvanMalison@gmail.com> @arianvp Arian van Putten <arian.vanputten@gmail.com> @flokli Florian Klink <flokli@flokli.de> @LordGrimmauld Sören Bender <soeren@benjos.de> @ElvishJerricco Will Fancher <elvishjerricco@gmail.com> @brianmcgillion Brian McGillion <bmg.avoin@gmail.com> @GaetanLepage Gaetan Lepage <gaetan@glepage.com> @liff Olli Helenius <liff@iki.fi> @mahyarmirrashed Mahyar Mirrashed <mah.mirr@gmail.com> @VuiMuich Johannes Mayrhofer <vuimuich@quantentunnel.de> @getchoo Seth Flynn <getchoo@tuta.io> @benley Benjamin Staffin <benley@gmail.com> @pasqui23 pasqui23 <p3dimaria@hotmail.it> @eadwu Edmund Wu <edmund.wu@protonmail.com> @kamadorueda Kevin Amado <kamadorueda@gmail.com>
pkgs.rpm-ostree Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model nixos-unstable - nixpkgs-unstable 2024.8
pkgs.systemd-lsp Language server implementation for systemd unit files made in Rust nixos-unstable - nixpkgs-unstable 0.1.0
pkgs.systemd-wait Wait for a systemd unit to enter a specific state nixos-unstable - nixpkgs-unstable 0.1+2018-10-05
pkgs.check_systemd Nagios / Icinga monitoring plugin to check systemd for failed units nixos-unstable - nixpkgs-unstable 5.0.0
pkgs.systemd-netlogd Forwards messages from the journal to other hosts over the network nixos-unstable - nixpkgs-unstable 1.4.4
pkgs.systemd-bootchart Boot performance graphing tool from systemd nixos-unstable - nixpkgs-unstable 235
pkgs.networkmanager-l2tp L2TP plugin for NetworkManager nixos-unstable - nixpkgs-unstable l2tp-gnome-1.20.20
pkgs.systemd-manager-tui Program for managing systemd services through a TUI nixos-unstable - nixpkgs-unstable 1.1.0
pkgs.systemd-lock-handler Translates systemd-system lock/sleep signals into systemd-user target activations nixos-unstable - nixpkgs-unstable 2.4.2
pkgs.networkmanager-iodine NetworkManager's iodine plugin nixos-unstable - nixpkgs-unstable 1.2.0-unstable-2025-09-06
pkgs.haskellPackages.systemd Systemd facilities (Socket activation, Notify) nixos-unstable - nixpkgs-unstable 2.4.0
pkgs.php81Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11
pkgs.php82Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11
pkgs.php83Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11
pkgs.php84Extensions.systemd PHP extension allowing native interaction with systemd and its journal nixos-unstable - nixpkgs-unstable 0.1.2-unstable-2018-06-11
pkgs.systemd-language-server Language Server for Systemd unit files nixos-unstable - nixpkgs-unstable 0.3.5
pkgs.update-systemd-resolved Helper script for OpenVPN to directly update the DNS settings of a link through systemd-resolved via DBus nixos-unstable - nixpkgs-unstable 1.3.0
pkgs.networkmanager_strongswan NetworkManager's strongswan plugin nixos-unstable - nixpkgs-unstable 1.6.2
pkgs.python312Packages.systemd Python module for native access to the systemd facilities nixos-unstable - nixpkgs-unstable 235
pkgs.python313Packages.systemd Python module for native access to the systemd facilities nixos-unstable - nixpkgs-unstable 235
pkgs.networkmanager-fortisslvpn NetworkManager’s FortiSSL plugin nixos-unstable - nixpkgs-unstable 1.4.0
pkgs.networkmanager-openconnect NetworkManager’s OpenConnect plugin nixos-unstable - nixpkgs-unstable 1.2.10
pkgs.nagiosPlugins.check_systemd Nagios / Icinga monitoring plugin to check systemd for failed units nixos-unstable - nixpkgs-unstable 5.0.0
pkgs.prometheus-systemd-exporter Exporter for systemd unit metrics nixos-unstable - nixpkgs-unstable 0.7.0
pkgs.haskellPackages.warp-systemd Socket activation and other systemd integration for the Warp web server (WAI) nixos-unstable - nixpkgs-unstable 0.3.0.0
pkgs.gnomeExtensions.systemd-manager GNOME Shell extension to manage systemd services nixos-unstable - nixpkgs-unstable 19
pkgs.haskellPackages.libsystemd-journal Haskell bindings to libsystemd-journal nixos-unstable - nixpkgs-unstable 1.4.6.0
pkgs.python312Packages.systemdunitparser SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files nixos-unstable - nixpkgs-unstable 0.4
pkgs.python313Packages.systemdunitparser SystemdUnitParser is an extension to Python's configparser.RawConfigParser to properly parse systemd unit files nixos-unstable - nixpkgs-unstable 0.4
pkgs.python312Packages.jupyterhub-systemdspawner JupyterHub Spawner using systemd for resource isolation nixos-unstable - nixpkgs-unstable 1.0.2
pkgs.python313Packages.jupyterhub-systemdspawner JupyterHub Spawner using systemd for resource isolation nixos-unstable - nixpkgs-unstable 1.0.2
pkgs.gnomeExtensions.systemd-offline-update-indicator Show an indicator for pending systemd offline updates. nixos-unstable - nixpkgs-unstable 7
pkgs.tests.pkg-config.defaultPkgConfigPackages.libudev Test whether systemd-257.8 exposes pkg-config modules libudev nixos-unstable - nixpkgs-unstable
pkgs.tests.pkg-config.defaultPkgConfigPackages.libsystemd Test whether systemd-257.8 exposes pkg-config modules libsystemd nixos-unstable - nixpkgs-unstable
CVE-2025-5054 created 4 months ago Race Condition in Canonical Apport Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before `consistency_checks`, which attempts to detect if the crashing process had been replaced. Because of this, if a process crashed and was quickly replaced with a containerized one, apport could be made to forward the core dump to the container, potentially leaking sensitive information. `consistency_checks` is now being called before `_check_global_pid_and_forward`. Additionally, given that the PID-reuse race condition cannot be reliably detected from userspace alone, crashes are only forwarded to containers if the kernel provided a pidfd, or if the crashing process was unprivileged (i.e., if dump mode == 1). Affected products apport <2.28.1-0ubuntu3.6 <2.20.9-0ubuntu7.29+esm1 <2.30.0-0ubuntu4.3 =<2.32.0 <2.20.11-0ubuntu27.28 <2.20.11-0ubuntu82.7 <2.32.0-0ubuntu5.1 <2.20.1-0ubuntu2.30+esm5 <2.32.0-0ubuntu6 <2.33.0-0ubuntu1 Matching in nixpkgs pkgs.haskellPackages.apportionment Round a set of numbers while maintaining its sum nixos-unstable - nixpkgs-unstable 0.0.0.4 Package maintainers: 1 @thielema Henning Thielemann <nix@henning-thielemann.de>
apport <2.28.1-0ubuntu3.6 <2.20.9-0ubuntu7.29+esm1 <2.30.0-0ubuntu4.3 =<2.32.0 <2.20.11-0ubuntu27.28 <2.20.11-0ubuntu82.7 <2.32.0-0ubuntu5.1 <2.20.1-0ubuntu2.30+esm5 <2.32.0-0ubuntu6 <2.33.0-0ubuntu1
pkgs.haskellPackages.apportionment Round a set of numbers while maintaining its sum nixos-unstable - nixpkgs-unstable 0.0.0.4