CVE-2025-9640 4.3 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 weeks, 5 days ago Samba: vfs_streams_xattr uninitialized memory write possible A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability. Affected products rhcos samba <4.23.2 <4.21.5 <4.21.9 samba4 Matching in nixpkgs pkgs.samba Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3 pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-25.05 4.20.8 nixpkgs-25.05-darwin 4.20.8 nixos-25.05-small 4.20.8 nixos-unstable 4.22.3 nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3 pkgs.sambamba SAM/BAM processing tool nixos-25.05 1.0.1 nixpkgs-25.05-darwin 1.0.1 nixos-25.05-small 1.0.1 nixos-unstable 1.0.1 nixos-unstable-small 1.0.1 nixpkgs-unstable 1.0.1 pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-25.05 4.20.8 nixpkgs-25.05-darwin 4.20.8 nixos-25.05-small 4.20.8 nixos-unstable 4.22.3 nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3 pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-25.05 4.20.8 nixpkgs-25.05-darwin 4.20.8 nixos-25.05-small 4.20.8 nixos-unstable 4.22.3 nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3 Package maintainers: 2 @aneeshusa Aneesh Agrawal <aneeshusa@gmail.com> @jbedo Justin Bedő <cu@cua0.org>
pkgs.samba Standard Windows interoperability suite of programs for Linux and Unix nixos-unstable ??? nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3
pkgs.samba4 Standard Windows interoperability suite of programs for Linux and Unix nixos-25.05 4.20.8 nixpkgs-25.05-darwin 4.20.8 nixos-25.05-small 4.20.8 nixos-unstable 4.22.3 nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3
pkgs.sambamba SAM/BAM processing tool nixos-25.05 1.0.1 nixpkgs-25.05-darwin 1.0.1 nixos-25.05-small 1.0.1 nixos-unstable 1.0.1 nixos-unstable-small 1.0.1 nixpkgs-unstable 1.0.1
pkgs.sambaFull Standard Windows interoperability suite of programs for Linux and Unix nixos-25.05 4.20.8 nixpkgs-25.05-darwin 4.20.8 nixos-25.05-small 4.20.8 nixos-unstable 4.22.3 nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3
pkgs.samba4Full Standard Windows interoperability suite of programs for Linux and Unix nixos-25.05 4.20.8 nixpkgs-25.05-darwin 4.20.8 nixos-25.05-small 4.20.8 nixos-unstable 4.22.3 nixos-unstable-small 4.22.3 nixpkgs-unstable 4.22.3
CVE-2025-11731 3.1 LOW CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 3 weeks, 5 days ago Libxslt: type confusion in exsltfuncresultcompfunction of libxslt A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service. Affected products rhcos libxslt <1.1.44 Matching in nixpkgs pkgs.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43 pkgs.python312Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43 pkgs.python313Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43 Package maintainers: 1 @jtojnar Jan Tojnar <jtojnar@gmail.com>
pkgs.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43
pkgs.python312Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43
pkgs.python313Packages.libxslt C library and tools to do XSL transformations nixos-25.05 1.1.43 nixpkgs-25.05-darwin 1.1.43 nixos-25.05-small 1.1.43 nixos-unstable 1.1.43 nixos-unstable-small 1.1.43 nixpkgs-unstable 1.1.43
CVE-2025-10283 9.6 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 weeks, 5 days ago Improper .git Sanitization in gitdumper Enables RCE BBOT's gitdumper module could be abused to execute commands through a malicious git repository. Affected products bbot =<2.6.1 Matching in nixpkgs pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20 Package maintainers: 1 @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com>
pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20
CVE-2025-10284 9.6 CRITICAL CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 weeks, 5 days ago Improper Archive Extraction in unarchive Enables RCE BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution. Affected products bbot =<2.6.1 Matching in nixpkgs pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20 Package maintainers: 1 @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com>
pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20
CVE-2025-10282 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 weeks, 5 days ago GitLab Domain Confusion in gitlab Leaks API Key BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL. Affected products bbot =<2.6.1 Matching in nixpkgs pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20 Package maintainers: 1 @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com>
pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20
CVE-2025-11561 8.8 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 3 weeks, 5 days ago Sssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systems A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, SSSD does not enable the Kerberos local authentication plugin (sssd_krb5_localauth_plugin), allowing an attacker with permission to modify certain AD attributes (such as userPrincipalName or samAccountName) to impersonate privileged users. This can result in unauthorized access or privilege escalation on domain-joined Linux hosts. Affected products sssd =<2.11.1 * rhcos * Matching in nixpkgs pkgs.sssd System Security Services Daemon nixos-25.05 2.9.5 nixpkgs-25.05-darwin 2.9.5 nixos-25.05-small 2.9.5 nixos-unstable 2.9.7 nixos-unstable-small 2.9.7 nixpkgs-unstable 2.9.7 Package maintainers: 1 @illustris Harikrishnan R <me@illustris.tech>
pkgs.sssd System Security Services Daemon nixos-25.05 2.9.5 nixpkgs-25.05-darwin 2.9.5 nixos-25.05-small 2.9.5 nixos-unstable 2.9.7 nixos-unstable-small 2.9.7 nixpkgs-unstable 2.9.7
CVE-2025-10281 4.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): NONE created 3 weeks, 5 days ago Insecure URL Handling in git_clone Leading to Leaked API Key BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL. Affected products bbot =<2.6.1 Matching in nixpkgs pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20 Package maintainers: 1 @a-kenji Alexander Kenji Berthold <aks.kenji@protonmail.com>
pkgs.hebbot Matrix bot which can generate "This Week in X" like blog posts nixos-25.05 2.1-unstable-2024-09-20 nixpkgs-25.05-darwin 2.1-unstable-2024-09-20 nixos-25.05-small 2.1-unstable-2024-09-20 nixos-unstable 2.1-unstable-2024-09-20 nixos-unstable-small 2.1-unstable-2024-09-20 nixpkgs-unstable 2.1-unstable-2024-09-20
CVE-2025-53881 created 3 weeks, 5 days ago SUSE-specific logrotate configuration allows escalation from mail user/group to root A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1. Affected products exim <4.98.2-lp156.248.1 Matching in nixpkgs pkgs.exim Mail transfer agent (MTA) nixos-25.05 4.98.2 nixpkgs-25.05-darwin 4.98.2 nixos-25.05-small 4.98.2 nixos-unstable 4.98.2 nixos-unstable-small 4.98.2 nixpkgs-unstable 4.98.2 Package maintainers: 4 @helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de> @dasJ Janne Heß <janne@hess.ooo> @4z3 Tomislav Viljetić <tv@krebsco.de> @Conni2461 Simon Hauser <simon-hauser@outlook.com>
pkgs.exim Mail transfer agent (MTA) nixos-25.05 4.98.2 nixpkgs-25.05-darwin 4.98.2 nixos-25.05-small 4.98.2 nixos-unstable 4.98.2 nixos-unstable-small 4.98.2 nixpkgs-unstable 4.98.2
CVE-2024-3049 7.4 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): NONE created 3 weeks, 5 days ago Booth: specially crafted hash can lead to invalid hmac being accepted by booth server A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server. Affected products booth ==1.0-283.1 * Matching in nixpkgs pkgs.libsForQt5.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3 pkgs.plasma5Packages.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3
pkgs.libsForQt5.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3
pkgs.plasma5Packages.booth Camera application nixos-25.05 1.1.3 nixpkgs-25.05-darwin 1.1.3 nixos-25.05-small 1.1.3
CVE-2025-54831 7.5 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 3 weeks, 5 days ago Apache Airflow: Connection sensitive details exposed to users with READ permissions Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values. In Airflow 3.0.3, this model was unintentionally violated: sensitive connection information could be viewed by users with READ permissions through both the API and the UI. This behavior also bypassed the `AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FIELDS` configuration option. This issue does not affect Airflow 2.x, where exposing sensitive information to connection editors was the intended and documented behavior. Users of Airflow 3.0.3 are advised to upgrade Airflow to >=3.0.4. Affected products apache-airflow ==3.0.3 Matching in nixpkgs pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-25.05-small 2.7.3 nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-25.05 2.7.3 nixpkgs-25.05-darwin 2.7.3 nixos-25.05-small 2.7.3 nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3