Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: mold-unwrapped

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-3994
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 2 months, 1 week ago by @pyrox0 Activity log
  • Created suggestion
  • @pyrox0 ignored
    3 packages
    • molden
    • home-assistant-component-tests.mold_indicator
    • tests.home-assistant-component-tests.mold_indicator
rui314 mold Object File input-files.cc initialize_sections heap-based overflow

A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

mold
  • ==2.40.3
  • ==2.40.0
  • ==2.40.1
  • ==2.40.2
  • ==2.40.4

Matching in nixpkgs

pkgs.mold

Faster drop-in replacement for existing Unix linkers (unwrapped)

pkgs.mold-wrapped

Faster drop-in replacement for existing Unix linkers (unwrapped) (wrapper script)

pkgs.mold-unwrapped

Faster drop-in replacement for existing Unix linkers (unwrapped)

Ignored packages (3)

pkgs.molden

Display and manipulate molecular structures

  • nixos-unstable 6.3
    • nixpkgs-unstable 6.3
    • nixos-unstable-small 6.3
  • nixos-25.11 6.3
    • nixos-25.11-small 6.3
    • nixpkgs-25.11-darwin 6.3

Package maintainers