Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: mold-unwrapped

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-3994
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 week, 3 days ago by @pyrox0 Activity log
  • Created automatic suggestion
  • @pyrox0 removed
    3 packages
    • molden
    • home-assistant-component-tests.mold_indicator
    • tests.home-assistant-component-tests.mold_indicator
rui314 mold Object File input-files.cc initialize_sections heap-based overflow

A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

mold
  • ==2.40.0
  • ==2.40.2
  • ==2.40.3
  • ==2.40.4
  • ==2.40.1

Matching in nixpkgs

Ignored packages (3)

pkgs.molden

Display and manipulate molecular structures

Package maintainers