Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: sing-geosite

Found 2 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-73450
7.0 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 6 days, 19 hours ago Activity log
  • Created suggestion
Security Advisory 0161

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch fails while these packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and err-disables its interfaces, leading to a traffic interruption.

References

Affected products

EOS
  • <4.33.0
  • =<4.36.1F
  • =<4.33.9M
  • =<4.34.7.1M
  • =<4.35.5M

Matching in nixpkgs

pkgs.geos

C/C++ library for computational geometry with a focus on algorithms used in geographic information systems (GIS) software

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teos

Lightning watchtower compliant with BOLT13, written in Rust

  • nixos-unstable -
    • nixos-unstable-small 0.2.0
  • nixos-26.05 -
    • nixos-26.05-small 0.2.0

pkgs.neosay

Pipe stdin to matrix

  • nixos-unstable -
    • nixos-unstable-small 1.0.1
  • nixos-26.05 -
    • nixos-26.05-small 1.0.1

pkgs.chameleos

Screen annotation tool for niri and Hyprland

  • nixos-unstable -
    • nixos-unstable-small 0.2.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.2

pkgs.geoserver

Open source server for sharing geospatial data

  • nixos-unstable -
  • nixos-26.05 -

pkgs.eos-installer

Installer UI which writes images to disk

  • nixos-unstable -
    • nixos-unstable-small 5.1.0
  • nixos-26.05 -
    • nixos-26.05-small 5.1.0

pkgs.collapseos-cvm

Virtual machine for Collapse OS (Forth operating system)

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.pyheos

Async python library for controlling HEOS devices through the HEOS CLI Protocol

  • nixos-unstable -
    • nixos-unstable-small 1.0.6
  • nixos-26.05 -
    • nixos-26.05-small 1.0.6

pkgs.python314Packages.pyheos

Async python library for controlling HEOS devices through the HEOS CLI Protocol

  • nixos-unstable -
    • nixos-unstable-small 1.0.6
  • nixos-26.05 -
    • nixos-26.05-small 1.0.6

Package maintainers

Permalink CVE-2026-73466
6.0 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): High (H)
  • Subsequent System Impact Availability (SA): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): High (H)
  • Modified Subsequent System Impact Availability (MSA): High (H)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week ago Activity log
  • Created suggestion
On affected platforms running Arista EOS, under certain circumstances plaintext user passwords

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

References

Affected products

EOS
  • =<4.33.9M
  • =<4.31.0
  • =<4.34.7M
  • =<4.36.1F
  • =<4.35.4M
  • =<4.32.0

Matching in nixpkgs

pkgs.geos

C/C++ library for computational geometry with a focus on algorithms used in geographic information systems (GIS) software

  • nixos-unstable -
  • nixos-26.05 -

pkgs.teos

Lightning watchtower compliant with BOLT13, written in Rust

  • nixos-unstable -
    • nixos-unstable-small 0.2.0
  • nixos-26.05 -
    • nixos-26.05-small 0.2.0

pkgs.neosay

Pipe stdin to matrix

  • nixos-unstable -
    • nixos-unstable-small 1.0.1
  • nixos-26.05 -
    • nixos-26.05-small 1.0.1

pkgs.chameleos

Screen annotation tool for niri and Hyprland

  • nixos-unstable -
    • nixos-unstable-small 0.2.1
  • nixos-26.05 -
    • nixos-26.05-small 0.1.2

pkgs.geoserver

Open source server for sharing geospatial data

  • nixos-unstable -
  • nixos-26.05 -

pkgs.eos-installer

Installer UI which writes images to disk

  • nixos-unstable -
    • nixos-unstable-small 5.1.0
  • nixos-26.05 -
    • nixos-26.05-small 5.1.0

pkgs.collapseos-cvm

Virtual machine for Collapse OS (Forth operating system)

  • nixos-unstable -
  • nixos-26.05 -

pkgs.python313Packages.pyheos

Async python library for controlling HEOS devices through the HEOS CLI Protocol

  • nixos-unstable -
    • nixos-unstable-small 1.0.6
  • nixos-26.05 -
    • nixos-26.05-small 1.0.6

pkgs.python314Packages.pyheos

Async python library for controlling HEOS devices through the HEOS CLI Protocol

  • nixos-unstable -
    • nixos-unstable-small 1.0.6
  • nixos-26.05 -
    • nixos-26.05-small 1.0.6

Package maintainers