Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-60134
8.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

Affected products

EasyWeb
  • ==2.3.17-typeb
  • <v2.1.20
cMT3092X firmware
  • <20210218
Dismissed
(max. allowed matches exceeded)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR

In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR When BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR, the module teardown path ends up calling pci_iounmap() on the same iomem with some offset, which is unnecessary and triggers a kernel warning like the following: Trying to vunmap() nonexistent vm area (0000000069a5ffe8) WARNING: mm/vmalloc.c:3470 at vunmap+0x58/0x68, CPU#5: modprobe/2937 [...] Call trace: vunmap+0x58/0x68 (P) iounmap+0x34/0x48 pci_iounmap+0x2c/0x40 ntb_epf_pci_remove+0x44/0x80 [ntb_hw_epf] pci_device_remove+0x48/0xf8 device_remove+0x50/0x88 device_release_driver_internal+0x1c8/0x228 driver_detach+0x50/0xb0 bus_remove_driver+0x74/0x100 driver_unregister+0x34/0x68 pci_unregister_driver+0x34/0xa0 ntb_epf_pci_driver_exit+0x14/0xfe0 [ntb_hw_epf] [...] Fix it by unmapping only when PEER_SPAD and CONFIG use difference bars.

Affected products

Linux
  • <9764a786ba98db58f0725913c369e721253aba33
  • <81371dbd23601f67f01372817fdbab42c5601e43
  • <6.0
  • =<6.18.*
  • <06f6dd2ff2bd07eaf7178a807407ff27e85122b4
  • =<6.12.*
  • =<7.1.*
  • <d876153680e3d721d385e554def919bce3d18c74
  • ==6.0
  • =<6.1.*
  • =<*
  • <eb47b9bffd07a47b84910847cb5ea066ce184055
  • =<6.6.*
  • <a4be4a1308f02bff79a30eea2d04ead5b63685f2
Dismissed
(exclusively hosted service)
Permalink CVE-2026-56165
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (exclusively hosted service) suggestion
Microsoft Account Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

Affected products

Microsoft Account
  • ==-
Dismissed
(max. allowed matches exceeded)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
octeontx2-af: CGX: add bounds check to cgx_speed_mbps index

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index cgx_speed_mbps has 13 elements but RESP_LINKSTAT_SPEED can yield values 0-15. If it returns a value >= 13, this causes an out-of-bounds array access. Add a bounds check and default to speed 0 if the index is out of range.

Affected products

Linux
  • <8201bf45cc7c1c1a09290c4db8ab1e19801f8fec
  • <2c3d26b4a62454945ba9ef3af3174d3e40e7afef
  • <93d3dc81098cd60fb74d434ba7985ddfd9de5acb
  • <e043017ac429caee73bd30c5a725659f1a3a4568
  • =<6.18.*
  • <47a4cf2229be379cf88f92e32e1240337cd6273f
  • =<5.10.*
  • =<7.0.*
  • <c0bf0a4f3f1f5f57aa83e1400ba4f56f0abfd542
  • =<6.12.*
  • <94071141f00bc414e8f8f7f5db3b5143d535299f
  • =<6.1.*
  • =<*
  • =<6.6.*
  • ==4.20
  • =<5.15.*
  • <4.20
  • <985b5e38ac4f4d5ff03c8bfd8484353b440a1579
Dismissed
(max. allowed matches exceeded)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
fpga: region: fix use-after-free in child_regions_with_firmware()

In the Linux kernel, the following vulnerability has been resolved: fpga: region: fix use-after-free in child_regions_with_firmware() Move of_node_put(child_region) after the error print to avoid accessing freed memory when pr_err() references child_region. [ Yilun: Fix the Fixes tag ]

Affected products

Linux
  • <e79afcb0a66d2b3c33e510eade902537e656fc00
  • <866184fc7ae42a0070f1141ae8c5dca7c24a59e2
  • <e918942bcc5355ad5b44ba557935dffc0727b0eb
  • <fbaf509ad7cb2f7dafe73ca20c956104cfcc9d68
  • =<6.18.*
  • <070b0ce947b18fa3dec0729695147f7e19599649
  • <54f3c5643ec523a04b6ec0e7c19eb10f5ebebdd3
  • =<6.12.*
  • =<7.1.*
  • <5e098e40e8bac43ed58645c10d5fad781966efe4
  • ==4.10
  • =<6.1.*
  • =<6.6.*
  • =<*
  • =<5.15.*
  • <369496d885b4cf6e8647cf4dc5cf3ac68fdf37a1
  • <4.10
  • =<5.10.*
Dismissed
(max. allowed matches exceeded)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table

In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table Check the return value of kzalloc() to prevent a NULL pointer dereference on allocation failure. Patchwork: https://patchwork.freedesktop.org/patch/721342/

Affected products

Linux
  • <17c993bf44a54afd1fde184ba7f9c287dfc2632e
  • =<7.0.*
  • ==6.19
  • =<*
  • <6.19
  • <b5c7a7f452b885bfbe102bd3a057a5f496802f8b
Dismissed
(no matching packages found)
Permalink CVE-2026-49743
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (no matching packages found) suggestion
GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.

Affected products

Graphics DDK
  • =<25.3 RTM
  • ==26.1 RTM1
  • ==1.18 RTM2
  • ==23.2 RTM2
  • ==26.1 RTM2
  • ==24.2 RTM2
Dismissed
(max. allowed matches exceeded)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config swing_tbl and pre_emphasis_tbl are 4x4 arrays (valid indices 0-3), but the boundary check uses "> 4" instead of ">= 4", allowing index 4 to cause an out-of-bounds access.

Affected products

Linux
  • ==7.0
  • =<7.0.*
  • =<*
  • <ea17fc4d7dc2ba6459b1a318962960520201baf1
  • <7.0
  • <cb35af6e7f3d5628178b58c631e305b1def8edf7
Dismissed
(no matching packages found)
Permalink CVE-2026-66142
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache Neethi: Uncontrolled recursion in policy processing

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Affected products

org.apache.neethi:neethi
  • <3.2.3
Dismissed
(exclusively hosted service)
Permalink CVE-2026-62835
9.3 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Unproven (U)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 2 days, 1 hour ago Activity log
  • Created & dismissed (exclusively hosted service) suggestion
Azure Portal Information Disclosure Vulnerability

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

References

Affected products

Azure Portal
  • ==-