Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
(not in Nixpkgs)
updated 1 week, 5 days ago by @jopejoe1 Activity log
  • Created suggestion
  • @jopejoe1 ignored
    11 packages
    • banana-vera
    • ubuntu-sans
    • ubuntu-themes
    • ubuntu-classic
    • ubuntu-sans-mono
    • nerd-fonts.ubuntu
    • kmod-blacklist-ubuntu
    • nerd-fonts.ubuntu-mono
    • nerd-fonts.ubuntu-sans
    • plymouth-vortex-ubuntu-theme
    • gnomeExtensions.ubuntu-net-speed
  • @jopejoe1 dismissed (not in Nixpkgs)
Senstive information disclosure was affecting ubuntu-desktop-provision

In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.

References

Affected products

ubuntu-desktop-provision
  • =<25.04
  • =<25.10
  • =<24.04.4
Ignored packages (11)

pkgs.ubuntu-themes

Ubuntu monochrome and Suru icon themes, Ambiance and Radiance themes, and Ubuntu artwork

pkgs.gnomeExtensions.ubuntu-net-speed

A simple extension that shows the current network speed

  • nixos-unstable 4
    • nixpkgs-unstable 4
    • nixos-unstable-small 4
  • nixos-25.11 4
    • nixos-25.11-small 4
    • nixpkgs-25.11-darwin 4