Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2026-3285
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 4 months, 4 weeks ago by @anthonyroussel Activity log
  • Created suggestion
  • @anthonyroussel ignored
    21 packages
    • berry
    • amiberry
    • blueberry
    • strawberry
    • yarn-berry
    • yarn-berry_3
    • yarn-berry_4
    • raspberrypifw
    • libraspberrypi
    • strawberry-qt6
    • device-tree_rpi
    • raspberrypi-eeprom
    • raspberrypi-armstubs
    • haskellPackages.huckleberry
    • raspberrypiWirelessFirmware
    • python312Packages.strawberry-django
    • python313Packages.strawberry-django
    • python312Packages.strawberry-graphql
    • python313Packages.strawberry-graphql
    • home-assistant-component-tests.raspberry_pi
    • tests.home-assistant-component-tests.raspberry_pi
  • @anthonyroussel dismissed
berry-lang berry be_lexer.c scan_string out-of-bounds

A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c59a39ba44feca261b12f06089f265fec176. Applying a patch is the recommended action to fix this issue.

Affected products

berry
  • ==1.0
  • ==1.1.0
Ignored packages (21)

pkgs.berry

Healthy, bite-sized window manager

pkgs.amiberry

Optimized Amiga emulator for Linux/macOS

pkgs.yarn-berry

Fast, reliable, and secure dependency management

pkgs.yarn-berry_3

Fast, reliable, and secure dependency management

Not present in nixpkgs (berry-lang)