Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2025-0650 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 weeks, 6 days ago Ovn: egress acls may be bypassed via specially crafted udp packet A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network. ovn ==22.03.8 ==24.03.5 ==24.09.2 ovn2.11 ovn2.12 ovn2.13 ovn-2021 ovn22.03 * ovn22.06 * ovn22.09 * ovn22.12 * ovn23.03 * ovn23.06 * ovn23.09 * ovn24.03 * ovn24.09 * pkgs.ovn Open Virtual Network nixos-24.11 24.09.1 nixpkgs-24.11-darwin 24.09.1 nixos-24.11-small 24.09.1 nixos-unstable 24.09.1 nixos-unstable-small 24.09.1 nixpkgs-unstable 24.09.1 pkgs.novnc VNC client web application nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 pkgs.ovn-lts Open Virtual Network nixos-24.05 24.03.2 nixpkgs-24.05-darwin 24.03.2 nixos-24.05-small 24.03.2 pkgs.turbovnc High-speed version of VNC derived from TightVNC nixos-24.05 3.1 nixpkgs-24.05-darwin 3.1 nixos-24.05-small 3.1 nixos-24.11 3.1.2 nixpkgs-24.11-darwin 3.1.2 nixos-24.11-small 3.1.2 nixos-unstable 3.1.3 nixos-unstable-small 3.1.3 nixpkgs-unstable 3.1.3 pkgs.nanovna-saver A tool for reading, displaying and saving data from the NanoVNA nixos-24.05 0.6.3 nixpkgs-24.05-darwin 0.6.3 nixos-24.05-small 0.6.3 nixos-24.11 0.6.4 nixpkgs-24.11-darwin 0.6.4 nixos-24.11-small 0.6.4 nixos-unstable 0.6.5 nixos-unstable-small 0.6.5 nixpkgs-unstable 0.6.5 pkgs.python311Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 nixos-24.11 0.6.0 nixpkgs-24.11-darwin 0.6.0 nixos-24.11-small 0.6.0 nixos-unstable 0.6.0 nixos-unstable-small 0.6.0 nixpkgs-unstable 0.6.0 pkgs.python312Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 Notify package maintainers: 6 @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net> @NeverBehave Xinhao Luo <i@never.pet> @nh2 Niklas Hambüchen <mail@nh2.me> @zaninime Francesco Zanini <francesco@zanini.me> @hesiod Tobias Markus <tobias@markus-regensburg.de> @npatsakula Patsakula Nikita <nikita.patsakula@gmail.com> CVE-2024-2313 2.8 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 weeks, 6 days ago If kernel headers need to be extracted, bpftrace will attempt … If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default. bpftrace <v0.20.2 pkgs.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxPackages_zen.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.emacsPackages.bpftrace-mode nixos-24.05 20190608.2201 nixpkgs-24.05-darwin 20190608.2201 nixos-24.05-small 20190608.2201 nixos-24.11 20190608.2201 nixpkgs-24.11-darwin 20190608.2201 nixos-24.11-small 20190608.2201 nixos-unstable 20190608.2201 nixos-unstable-small 20190608.2201 nixpkgs-unstable 20190608.2201 pkgs.linuxKernel.packages.linux_6_1.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_lqx.bpftrace High-level tracing language for Linux eBPF nixos-24.11 ??? nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 pkgs.linuxKernel.packages.linux_4_19.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_5_10.bpftrace High-level tracing language for Linux eBPF nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxKernel.packages.linux_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-24.11 0.21.2 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_hardened.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_latest_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 Notify package maintainers: 4 @rvl Rodney Lorrimar <dev+nix@rodney.id.au> @mfrw Muhammad Falak R Wani <falakreyaz@gmail.com> @thoughtpolice Austin Seipp <aseipp@pobox.com> @martinetd Dominique Martinet <f.ktfhrvnznqxacf@noclue.notk.org> CVE-2024-43437 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 weeks, 6 days ago Moodle: xss risk when restoring malicious course backup file A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. moodle <4.2.9 <4.4.2 <4.1.12 <4.3.6 pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-24.05 4.4 nixpkgs-24.05-darwin 4.4 nixos-24.05-small 4.4 nixos-24.11 4.4.3 nixpkgs-24.11-darwin 4.4.3 nixos-24.11-small 4.4.3 nixos-unstable 4.4.3 nixos-unstable-small 4.4.4 nixpkgs-unstable 4.4.3 pkgs.moodle-dl A Moodle downloader that downloads course content fast from Moodle nixos-24.05 2.2.2.4 nixpkgs-24.05-darwin 2.2.2.4 nixos-24.05-small 2.2.2.4 nixos-24.11 2.3.12 nixpkgs-24.11-darwin 2.3.12 nixos-24.11-small 2.3.12 nixos-unstable 2.3.12 nixos-unstable-small 2.3.12 nixpkgs-unstable 2.3.12 pkgs.texlivePackages.moodle Generating Moodle quizzes via LaTeX nixos-24.05 1.0 nixpkgs-24.05-darwin 1.0 nixos-24.05-small 1.0 Notify package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de> CVE-2023-26020 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): HIGH created 3 weeks ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Crafter Studio Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26. Studio =<4.0.1 =<3.1.26 pkgs.rstudio Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudio-server Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudioWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.rstudioServerWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-24.05 1.2.30 nixpkgs-24.05-darwin 1.2.30 nixos-24.05-small 1.2.30 nixos-24.11 1.3.2 nixpkgs-24.11-darwin 1.3.2 nixos-24.11-small 1.3.2 nixos-unstable 1.3.2 nixos-unstable-small 1.3.2 nixpkgs-unstable 1.3.2 pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-24.05 0.2.8 nixpkgs-24.05-darwin 0.2.8 nixos-24.05-small 0.2.8 nixos-24.11 0.2.9 nixpkgs-24.11-darwin 0.2.9 nixos-24.11-small 0.2.9 nixos-unstable 0.2.9 nixos-unstable-small 0.2.9 nixpkgs-unstable 0.2.9 Notify package maintainers: 3 @cfhammill Chris Hammill <cfhammill@gmail.com> @ciil Simon Lackerbauer <simon@lackerbauer.com> @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru> CVE-2025-27274 4.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 4 weeks, 2 days ago WordPress GPX Viewer plugin <= 2.2.11 - Path Traversal vulnerability Path Traversal vulnerability in NotFound GPX Viewer allows Path Traversal. This issue affects GPX Viewer: from n/a through 2.2.11. gpx-viewer =<2.2.11 pkgs.gpx-viewer Simple tool to visualize tracks and waypoints stored in a gpx file nixos-24.05 0.5.0 nixpkgs-24.05-darwin 0.5.0 nixos-24.05-small 0.5.0 nixos-24.11 0.5.0 nixpkgs-24.11-darwin 0.5.0 nixos-24.11-small 0.5.0 nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0 Notify package maintainers: 1 @dotlambda Robert Schütz <rschuetz17@gmail.com> CVE-2023-3899 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Subscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configuration A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root. subscription-manager * pkgs.python311Packages.graphql-subscription-manager Python3 library for graphql subscription manager nixos-24.05 0.7.1 nixpkgs-24.05-darwin 0.7.1 nixos-24.05-small 0.7.1 nixos-24.11 0.7.1 nixpkgs-24.11-darwin 0.7.1 nixos-24.11-small 0.7.1 nixos-unstable 0.7.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1 pkgs.python312Packages.graphql-subscription-manager Python3 library for graphql subscription manager nixos-24.05 0.7.1 nixpkgs-24.05-darwin 0.7.1 nixos-24.05-small 0.7.1 nixos-24.11 0.7.1 nixpkgs-24.11-darwin 0.7.1 nixos-24.11-small 0.7.1 nixos-unstable 0.7.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1 Notify package maintainers: 1 @dotlambda Robert Schütz <rschuetz17@gmail.com> CVE-2025-26595 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Xorg: xwayland: buffer overflow in xkbvmodmasktext() A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name> CVE-2025-26597 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Xorg: xwayland: buffer overflow in xkbchangetypesofkey() A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name> CVE-2025-26594 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago X.org: xwayland: use-after-free of the root cursor A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name> CVE-2025-26599 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Xorg: xwayland: use of uninitialized pointer in compredirectwindow() An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name>
CVE-2025-0650 8.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 2 weeks, 6 days ago Ovn: egress acls may be bypassed via specially crafted udp packet A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network. ovn ==22.03.8 ==24.03.5 ==24.09.2 ovn2.11 ovn2.12 ovn2.13 ovn-2021 ovn22.03 * ovn22.06 * ovn22.09 * ovn22.12 * ovn23.03 * ovn23.06 * ovn23.09 * ovn24.03 * ovn24.09 * pkgs.ovn Open Virtual Network nixos-24.11 24.09.1 nixpkgs-24.11-darwin 24.09.1 nixos-24.11-small 24.09.1 nixos-unstable 24.09.1 nixos-unstable-small 24.09.1 nixpkgs-unstable 24.09.1 pkgs.novnc VNC client web application nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0 pkgs.ovn-lts Open Virtual Network nixos-24.05 24.03.2 nixpkgs-24.05-darwin 24.03.2 nixos-24.05-small 24.03.2 pkgs.turbovnc High-speed version of VNC derived from TightVNC nixos-24.05 3.1 nixpkgs-24.05-darwin 3.1 nixos-24.05-small 3.1 nixos-24.11 3.1.2 nixpkgs-24.11-darwin 3.1.2 nixos-24.11-small 3.1.2 nixos-unstable 3.1.3 nixos-unstable-small 3.1.3 nixpkgs-unstable 3.1.3 pkgs.nanovna-saver A tool for reading, displaying and saving data from the NanoVNA nixos-24.05 0.6.3 nixpkgs-24.05-darwin 0.6.3 nixos-24.05-small 0.6.3 nixos-24.11 0.6.4 nixpkgs-24.11-darwin 0.6.4 nixos-24.11-small 0.6.4 nixos-unstable 0.6.5 nixos-unstable-small 0.6.5 nixpkgs-unstable 0.6.5 pkgs.python311Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 nixos-24.11 0.6.0 nixpkgs-24.11-darwin 0.6.0 nixos-24.11-small 0.6.0 nixos-unstable 0.6.0 nixos-unstable-small 0.6.0 nixpkgs-unstable 0.6.0 pkgs.python312Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 Notify package maintainers: 6 @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net> @NeverBehave Xinhao Luo <i@never.pet> @nh2 Niklas Hambüchen <mail@nh2.me> @zaninime Francesco Zanini <francesco@zanini.me> @hesiod Tobias Markus <tobias@markus-regensburg.de> @npatsakula Patsakula Nikita <nikita.patsakula@gmail.com>
pkgs.ovn Open Virtual Network nixos-24.11 24.09.1 nixpkgs-24.11-darwin 24.09.1 nixos-24.11-small 24.09.1 nixos-unstable 24.09.1 nixos-unstable-small 24.09.1 nixpkgs-unstable 24.09.1
pkgs.novnc VNC client web application nixos-24.05 1.4.0 nixpkgs-24.05-darwin 1.4.0 nixos-24.05-small 1.4.0 nixos-24.11 1.5.0 nixpkgs-24.11-darwin 1.5.0 nixos-24.11-small 1.5.0 nixos-unstable 1.5.0 nixos-unstable-small 1.5.0 nixpkgs-unstable 1.5.0
pkgs.ovn-lts Open Virtual Network nixos-24.05 24.03.2 nixpkgs-24.05-darwin 24.03.2 nixos-24.05-small 24.03.2
pkgs.turbovnc High-speed version of VNC derived from TightVNC nixos-24.05 3.1 nixpkgs-24.05-darwin 3.1 nixos-24.05-small 3.1 nixos-24.11 3.1.2 nixpkgs-24.11-darwin 3.1.2 nixos-24.11-small 3.1.2 nixos-unstable 3.1.3 nixos-unstable-small 3.1.3 nixpkgs-unstable 3.1.3
pkgs.nanovna-saver A tool for reading, displaying and saving data from the NanoVNA nixos-24.05 0.6.3 nixpkgs-24.05-darwin 0.6.3 nixos-24.05-small 0.6.3 nixos-24.11 0.6.4 nixpkgs-24.11-darwin 0.6.4 nixos-24.11-small 0.6.4 nixos-unstable 0.6.5 nixos-unstable-small 0.6.5 nixpkgs-unstable 0.6.5
pkgs.python311Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0 nixos-24.11 0.6.0 nixpkgs-24.11-darwin 0.6.0 nixos-24.11-small 0.6.0 nixos-unstable 0.6.0 nixos-unstable-small 0.6.0 nixpkgs-unstable 0.6.0
pkgs.python312Packages.slovnet Deep-learning based NLP modeling for Russian language nixos-24.05 0.6.0 nixpkgs-24.05-darwin 0.6.0 nixos-24.05-small 0.6.0
CVE-2024-2313 2.8 LOW CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): LOW created 2 weeks, 6 days ago If kernel headers need to be extracted, bpftrace will attempt … If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default. bpftrace <v0.20.2 pkgs.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxPackages_zen.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.emacsPackages.bpftrace-mode nixos-24.05 20190608.2201 nixpkgs-24.05-darwin 20190608.2201 nixos-24.05-small 20190608.2201 nixos-24.11 20190608.2201 nixpkgs-24.11-darwin 20190608.2201 nixos-24.11-small 20190608.2201 nixos-unstable 20190608.2201 nixos-unstable-small 20190608.2201 nixpkgs-unstable 20190608.2201 pkgs.linuxKernel.packages.linux_6_1.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_lqx.bpftrace High-level tracing language for Linux eBPF nixos-24.11 ??? nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 pkgs.linuxKernel.packages.linux_4_19.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_5_10.bpftrace High-level tracing language for Linux eBPF nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 pkgs.linuxKernel.packages.linux_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-24.11 0.21.2 nixos-unstable 0.21.2 pkgs.linuxKernel.packages.linux_hardened.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 pkgs.linuxKernel.packages.linux_latest_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2 Notify package maintainers: 4 @rvl Rodney Lorrimar <dev+nix@rodney.id.au> @mfrw Muhammad Falak R Wani <falakreyaz@gmail.com> @thoughtpolice Austin Seipp <aseipp@pobox.com> @martinetd Dominique Martinet <f.ktfhrvnznqxacf@noclue.notk.org>
pkgs.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
pkgs.linuxPackages_zen.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4 nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
pkgs.emacsPackages.bpftrace-mode nixos-24.05 20190608.2201 nixpkgs-24.05-darwin 20190608.2201 nixos-24.05-small 20190608.2201 nixos-24.11 20190608.2201 nixpkgs-24.11-darwin 20190608.2201 nixos-24.11-small 20190608.2201 nixos-unstable 20190608.2201 nixos-unstable-small 20190608.2201 nixpkgs-unstable 20190608.2201
pkgs.linuxKernel.packages.linux_6_1.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2
pkgs.linuxKernel.packages.linux_lqx.bpftrace High-level tracing language for Linux eBPF nixos-24.11 ??? nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2
pkgs.linuxKernel.packages.linux_4_19.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4
pkgs.linuxKernel.packages.linux_5_10.bpftrace High-level tracing language for Linux eBPF nixos-24.11 0.21.2 nixpkgs-24.11-darwin 0.21.2 nixos-24.11-small 0.21.2 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
pkgs.linuxKernel.packages.linux_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-24.11 0.21.2 nixos-unstable 0.21.2
pkgs.linuxKernel.packages.linux_hardened.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixpkgs-24.05-darwin 0.20.4 nixos-24.05-small 0.20.4
pkgs.linuxKernel.packages.linux_latest_libre.bpftrace High-level tracing language for Linux eBPF nixos-24.05 0.20.4 nixos-unstable 0.21.2 nixos-unstable-small 0.21.2 nixpkgs-unstable 0.21.2
CVE-2024-43437 5.4 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): NONE created 2 weeks, 6 days ago Moodle: xss risk when restoring malicious course backup file A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. moodle <4.2.9 <4.4.2 <4.1.12 <4.3.6 pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-24.05 4.4 nixpkgs-24.05-darwin 4.4 nixos-24.05-small 4.4 nixos-24.11 4.4.3 nixpkgs-24.11-darwin 4.4.3 nixos-24.11-small 4.4.3 nixos-unstable 4.4.3 nixos-unstable-small 4.4.4 nixpkgs-unstable 4.4.3 pkgs.moodle-dl A Moodle downloader that downloads course content fast from Moodle nixos-24.05 2.2.2.4 nixpkgs-24.05-darwin 2.2.2.4 nixos-24.05-small 2.2.2.4 nixos-24.11 2.3.12 nixpkgs-24.11-darwin 2.3.12 nixos-24.11-small 2.3.12 nixos-unstable 2.3.12 nixos-unstable-small 2.3.12 nixpkgs-unstable 2.3.12 pkgs.texlivePackages.moodle Generating Moodle quizzes via LaTeX nixos-24.05 1.0 nixpkgs-24.05-darwin 1.0 nixos-24.05-small 1.0 Notify package maintainers: 2 @freezeboy freezeboy @kmein Kierán Meinhardt <kmein@posteo.de>
pkgs.moodle Free and open-source learning management system (LMS) written in PHP nixos-24.05 4.4 nixpkgs-24.05-darwin 4.4 nixos-24.05-small 4.4 nixos-24.11 4.4.3 nixpkgs-24.11-darwin 4.4.3 nixos-24.11-small 4.4.3 nixos-unstable 4.4.3 nixos-unstable-small 4.4.4 nixpkgs-unstable 4.4.3
pkgs.moodle-dl A Moodle downloader that downloads course content fast from Moodle nixos-24.05 2.2.2.4 nixpkgs-24.05-darwin 2.2.2.4 nixos-24.05-small 2.2.2.4 nixos-24.11 2.3.12 nixpkgs-24.11-darwin 2.3.12 nixos-24.11-small 2.3.12 nixos-unstable 2.3.12 nixos-unstable-small 2.3.12 nixpkgs-unstable 2.3.12
pkgs.texlivePackages.moodle Generating Moodle quizzes via LaTeX nixos-24.05 1.0 nixpkgs-24.05-darwin 1.0 nixos-24.05-small 1.0
CVE-2023-26020 5.7 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): HIGH Privileges required (PR): HIGH User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): HIGH Availability impact (A): HIGH created 3 weeks ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Crafter Studio Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26. Studio =<4.0.1 =<3.1.26 pkgs.rstudio Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudio-server Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764 pkgs.rstudioWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.rstudioServerWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-24.05 1.2.30 nixpkgs-24.05-darwin 1.2.30 nixos-24.05-small 1.2.30 nixos-24.11 1.3.2 nixpkgs-24.11-darwin 1.3.2 nixos-24.11-small 1.3.2 nixos-unstable 1.3.2 nixos-unstable-small 1.3.2 nixpkgs-unstable 1.3.2 pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-24.05 0.2.8 nixpkgs-24.05-darwin 0.2.8 nixos-24.05-small 0.2.8 nixos-24.11 0.2.9 nixpkgs-24.11-darwin 0.2.9 nixos-24.11-small 0.2.9 nixos-unstable 0.2.9 nixos-unstable-small 0.2.9 nixpkgs-unstable 0.2.9 Notify package maintainers: 3 @cfhammill Chris Hammill <cfhammill@gmail.com> @ciil Simon Lackerbauer <simon@lackerbauer.com> @TheMaxMur Maxim Muravev <muravjev.mak@yandex.ru>
pkgs.rstudio Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764
pkgs.rstudio-server Set of integrated tools for the R language nixos-24.05 2023.12.1+402 nixpkgs-24.05-darwin 2023.12.1+402 nixos-24.05-small 2023.12.1+402 nixos-24.11 2024.04.2+764 nixpkgs-24.11-darwin 2024.04.2+764 nixos-24.11-small 2024.04.2+764 nixos-unstable 2024.04.2+764 nixos-unstable-small 2024.04.2+764 nixpkgs-unstable 2024.04.2+764
pkgs.rstudioWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper
pkgs.rstudioServerWrapper nixos-24.05 2023.12.1+402-wrapper nixpkgs-24.05-darwin 2023.12.1+402-wrapper nixos-24.05-small 2023.12.1+402-wrapper nixos-24.11 2024.04.2+764-wrapper nixpkgs-24.11-darwin 2024.04.2+764-wrapper nixos-24.11-small 2024.04.2+764-wrapper nixos-unstable 2024.04.2+764-wrapper nixos-unstable-small 2024.04.2+764-wrapper nixpkgs-unstable 2024.04.2+764-wrapper
pkgs.vscode-extensions.visualstudioexptteam.vscodeintellicode AI-assisted development nixos-24.05 1.2.30 nixpkgs-24.05-darwin 1.2.30 nixos-24.05-small 1.2.30 nixos-24.11 1.3.2 nixpkgs-24.11-darwin 1.3.2 nixos-24.11-small 1.3.2 nixos-unstable 1.3.2 nixos-unstable-small 1.3.2 nixpkgs-unstable 1.3.2
pkgs.vscode-extensions.visualstudioexptteam.intellicode-api-usage-examples See relevant code examples from GitHub for over 100K different APIs right in your editor nixos-24.05 0.2.8 nixpkgs-24.05-darwin 0.2.8 nixos-24.05-small 0.2.8 nixos-24.11 0.2.9 nixpkgs-24.11-darwin 0.2.9 nixos-24.11-small 0.2.9 nixos-unstable 0.2.9 nixos-unstable-small 0.2.9 nixpkgs-unstable 0.2.9
CVE-2025-27274 4.9 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 4 weeks, 2 days ago WordPress GPX Viewer plugin <= 2.2.11 - Path Traversal vulnerability Path Traversal vulnerability in NotFound GPX Viewer allows Path Traversal. This issue affects GPX Viewer: from n/a through 2.2.11. gpx-viewer =<2.2.11 pkgs.gpx-viewer Simple tool to visualize tracks and waypoints stored in a gpx file nixos-24.05 0.5.0 nixpkgs-24.05-darwin 0.5.0 nixos-24.05-small 0.5.0 nixos-24.11 0.5.0 nixpkgs-24.11-darwin 0.5.0 nixos-24.11-small 0.5.0 nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0 Notify package maintainers: 1 @dotlambda Robert Schütz <rschuetz17@gmail.com>
pkgs.gpx-viewer Simple tool to visualize tracks and waypoints stored in a gpx file nixos-24.05 0.5.0 nixpkgs-24.05-darwin 0.5.0 nixos-24.05-small 0.5.0 nixos-24.11 0.5.0 nixpkgs-24.11-darwin 0.5.0 nixos-24.11-small 0.5.0 nixos-unstable 0.5.0 nixos-unstable-small 0.5.0 nixpkgs-unstable 0.5.0
CVE-2023-3899 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month ago Subscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configuration A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root. subscription-manager * pkgs.python311Packages.graphql-subscription-manager Python3 library for graphql subscription manager nixos-24.05 0.7.1 nixpkgs-24.05-darwin 0.7.1 nixos-24.05-small 0.7.1 nixos-24.11 0.7.1 nixpkgs-24.11-darwin 0.7.1 nixos-24.11-small 0.7.1 nixos-unstable 0.7.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1 pkgs.python312Packages.graphql-subscription-manager Python3 library for graphql subscription manager nixos-24.05 0.7.1 nixpkgs-24.05-darwin 0.7.1 nixos-24.05-small 0.7.1 nixos-24.11 0.7.1 nixpkgs-24.11-darwin 0.7.1 nixos-24.11-small 0.7.1 nixos-unstable 0.7.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1 Notify package maintainers: 1 @dotlambda Robert Schütz <rschuetz17@gmail.com>
pkgs.python311Packages.graphql-subscription-manager Python3 library for graphql subscription manager nixos-24.05 0.7.1 nixpkgs-24.05-darwin 0.7.1 nixos-24.05-small 0.7.1 nixos-24.11 0.7.1 nixpkgs-24.11-darwin 0.7.1 nixos-24.11-small 0.7.1 nixos-unstable 0.7.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1
pkgs.python312Packages.graphql-subscription-manager Python3 library for graphql subscription manager nixos-24.05 0.7.1 nixpkgs-24.05-darwin 0.7.1 nixos-24.05-small 0.7.1 nixos-24.11 0.7.1 nixpkgs-24.11-darwin 0.7.1 nixos-24.11-small 0.7.1 nixos-unstable 0.7.1 nixos-unstable-small 0.7.1 nixpkgs-unstable 0.7.1
CVE-2025-26595 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Xorg: xwayland: buffer overflow in xkbvmodmasktext() A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name>
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0
CVE-2025-26597 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Xorg: xwayland: buffer overflow in xkbchangetypesofkey() A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name>
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0
CVE-2025-26594 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago X.org: xwayland: use-after-free of the root cursor A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name>
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0
CVE-2025-26599 7.8 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 1 month, 1 week ago Xorg: xwayland: use of uninitialized pointer in compredirectwindow() An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later. tigervnc xorg-x11-server xorg-x11-server-Xwayland pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0 Notify package maintainers: 1 @viric Lluís Batlle i Rossell <viric@viric.name>
pkgs.tigervnc Fork of tightVNC, made in cooperation with VirtualGL nixos-24.05 1.13.1 nixpkgs-24.05-darwin 1.13.1 nixos-24.05-small 1.13.1 nixos-24.11 1.14.0 nixpkgs-24.11-darwin 1.14.0 nixos-24.11-small 1.14.0 nixos-unstable 1.14.0 nixos-unstable-small 1.14.0 nixpkgs-unstable 1.14.0