Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: nagiosPlugins.check_esxi_hardware

Found 3 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-41703
7.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 5 days, 4 hours ago Activity log
  • Created suggestion
Out-of-bounds read vulnerability

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

Affected products

ESX
  • <ESXi-9.1.0.0-25370933
  • <ESXi-9.0.2.0100-25595025
  • <ESXi80U3i-25205845
Fusion
  • <26H1
Workstation
  • <26H1
Cloud Foundation
  • <5.2.3
  • ==9.1.x.x
  • ==9.0.x.x
vSphere Foundation
  • ==9.1.x.x
  • ==9.0.x.x
Telco Cloud Platform
  • ==5.0.x
  • ==5.1.x

Matching in nixpkgs

pkgs.fusionInventory

FusionInventory unified Agent for UNIX, Linux, Windows and MacOSX

  • nixos-unstable 2.6
    • nixpkgs-unstable 2.6
    • nixos-unstable-small 2.6
  • nixos-26.05 2.6
    • nixos-26.05-small 2.6
    • nixpkgs-26.05-darwin 2.6

pkgs.helio-workstation

One music sequencer for all major platforms, both desktop and mobile

  • nixos-unstable 3.17
    • nixpkgs-unstable 3.17
    • nixos-unstable-small 3.17
  • nixos-26.05 3.17
    • nixos-26.05-small 3.17
    • nixpkgs-26.05-darwin 3.17

pkgs.fusioninventory-agent

FusionInventory unified Agent for UNIX, Linux, Windows and MacOSX

  • nixos-unstable 2.6
    • nixpkgs-unstable 2.6
    • nixos-unstable-small 2.6
  • nixos-26.05 2.6
    • nixos-26.05-small 2.6
    • nixpkgs-26.05-darwin 2.6

Package maintainers

Untriaged
Permalink CVE-2026-41709
2.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 5 days, 4 hours ago Activity log
  • Created suggestion
ESX insufficient logging vulnerability

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

Affected products

ESX
  • <ESXi80U3j-25429389
  • <ESXi-9.1.0.0-25370933
  • <ESXi-9.0.2.0100-25595025
Cloud Foundation
  • <5.2.4
  • ==9.1.x.x
  • ==9.0.x.x
vSphere Foundation
  • ==9.1.x.x
  • ==9.0.x.x
Telco Cloud Platform
  • ==5.0.x
  • ==5.1.x

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2026-47876
9.3 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 5 days, 4 hours ago Activity log
  • Created suggestion
VMXNET3 out-of-bounds write vulnerability

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Affected products

ESX
  • <ESXi-9.0.2.0100-25595025
  • <ESXi80U3k-25595708
  • <ESXi-9.1.0.0200-25557999
Cloud Foundation
  • ==9.1.x.x
  • ==5.x
  • ==9.0.x.x
vSphere Foundation
  • ==9.1.x.x
  • ==9.0.x.x
Telco Cloud Platform
  • ==5.0.x
  • ==5.1.x

Matching in nixpkgs

Package maintainers