NIXPKGS-2026-0207
GitHub issue
published on 10 Feb 2026
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
6 packages
- vscode-extensions.janet-lang.vscode-janet
- tree-sitter-grammars.tree-sitter-janet-simple
- vimPlugins.nvim-treesitter-parsers.janet_simple
- python312Packages.tree-sitter-grammars.tree-sitter-janet-simple
- python313Packages.tree-sitter-grammars.tree-sitter-janet-simple
- python314Packages.tree-sitter-grammars.tree-sitter-janet-simple
- @LeSuisse accepted
- @LeSuisse published on GitHub
janet-lang janet os.c os_strftime out-of-bounds
A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is named 0f285855f0e34f9183956be5f16e045f54626bff. To fix this issue, it is recommended to deploy a patch.
Affected products
janet
- ==1.40.1
- ==1.40.0
Matching in nixpkgs
Ignored packages (6)
pkgs.vscode-extensions.janet-lang.vscode-janet
Janet language support for Visual Studio Code
-
nixos-unstable 0.0.7-unstable-2025-05-19
- nixpkgs-unstable 0.0.7-unstable-2025-05-19
- nixos-unstable-small 0.0.7-unstable-2025-05-19
-
nixos-unstable 0.0.0+rev=7e28cbf
- nixpkgs-unstable 0.0.0+rev=7e28cbf
- nixos-unstable-small 0.0.0+rev=7e28cbf
pkgs.python312Packages.tree-sitter-grammars.tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
-
nixos-unstable 0.0.7+unstable20250519
- nixpkgs-unstable 0.0.7+unstable20250519
- nixos-unstable-small 0.0.7+unstable20250519
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-janet-simple
Python bindings for tree-sitter-janet-simple
-
nixos-unstable 0.0.7+unstable20250519
- nixpkgs-unstable 0.0.7+unstable20250519
- nixos-unstable-small 0.0.7+unstable20250519
Package maintainers
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@andrewchambers Andrew Chambers <ac@acha.ninja>
-
@mightyiam Shahar "Dawn" Or <mightyiampresence@gmail.com>
-
@A-jay98 Ali Jamadi <ali@jamadi.me>
-
@adfaure Adrien Faure <adfaure@pm.me>
-
@stepbrobd Yifei Sun <ysun@hey.com>
-
@wackbyte wackbyte <wackbyte@pm.me>