Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0075

NIXPKGS-2026-0075
published on 21 Jan 2026
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package libcdio-paranoia
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Buffer Overflow Vulnerability in libcdio v2.1.0 allows an attacker to …

Buffer Overflow Vulnerability in libcdio v2.1.0 allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

Affected products

n/a
  • ==n/a
libcdio
  • ==2.1.0

Matching in nixpkgs

Upstream fix: https://github.com/libcdio/libcdio/commit/417478a7474af41c27ab3f876f31783fa06a5dbc
Fixed in 2.3.0: https://github.com/libcdio/libcdio/releases/tag/2.3.0