Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47405
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Untrusted Pointer Dereference in Camera

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

Affected products

Snapdragon
  • ==SC8380XP
  • ==WSA8810
  • ==WSA8815
  • ==FastConnect 7800
  • ==SD865 5G
  • ==WCD9380
  • ==FastConnect 6900
  • ==WCD9385
  • ==WSA8845
  • ==WSA8845H
  • ==WSA8840
  • ==Snapdragon XR2 5G Platform
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==IQX5121
  • ==IQX7181
  • ==QCA0000

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25266
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Exposed dangerous function in windows host

Memory corruption while processing IOCTL command when device is in power-save state.

Affected products

Snapdragon
  • ==WSA8835
  • ==Cologne
  • ==WCD9385
  • ==WCN7861
  • ==WSA8845
  • ==XG101002
  • ==WSA8830
  • ==XG101032
  • ==SC8380XP
  • ==X2000077
  • ==X2000094
  • ==Snapdragon AR1 Gen 1 Platform
  • ==X2000086
  • ==WCD9378C
  • ==X2000092
  • ==FastConnect 7800
  • ==WSA8832
  • ==FastConnect 6900
  • ==XG101039
  • ==WCN7880
  • ==WSA8840
  • ==X2000090
  • ==WCD9380
  • ==WSA8845H

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47407
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.

Affected products

Snapdragon
  • ==XRV9209
  • ==WSA8845
  • ==QPA1083BD
  • ==SM6850
  • ==SC8380XP
  • ==WCN6755
  • ==SM8750P
  • ==QMP1000
  • ==SM6450P
  • ==Snapdragon 662 Mobile Platform
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==QLN1086BD
  • ==QCS4290
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==WCD9395
  • ==Molokai
  • ==QLN1083BD
  • ==Netrani
  • ==SM7435P
  • ==Themisto
  • ==SXR2350P
  • ==SW5100
  • ==WCN7760
  • ==QXM1096
  • ==SM6225P
  • ==QMP2001
  • ==Snapdragon 8 Elite
  • ==QPA1086BD
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FastConnect 7800
  • ==WCN6450
  • ==QCM2290
  • ==SAR1165P
  • ==WCN7881
  • ==SM6475P
  • ==Snapdragon 8 Elite Gen 5
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==Snapdragon Wear Elite platform
  • ==WSA8815
  • ==WCD9380
  • ==Orne
  • ==Snapdragon 7 Gen 4 Mobile Platform
  • ==WSA8845H
  • ==WCN7860
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==WSA8835
  • ==WCN3980
  • ==SXR2250P
  • ==WCN3988
  • ==WCN7861
  • ==X1E80100
  • ==Palawan25
  • ==Snapdragon XR2 5G Platform
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==WSA8850
  • ==Snapdragon 685 4G Mobile Platform
  • ==WCD9370
  • ==QCM4325
  • ==Snapdragon 680 4G Mobile Platform
  • ==WSA8832
  • ==FastConnect 6900
  • ==WCN7880
  • ==QCS2290
  • ==SXR2230P
  • ==FastConnect 6200
  • ==WCN3950
  • ==SAR2130P
  • ==CQ7790
  • ==SXR2330P
  • ==SD865 5G
  • ==WCD9385
  • ==QMB715
  • ==WSA8850W
  • ==WSA8830
  • ==WSA8855C
  • ==SD662
  • ==WCD9375
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==SM7435
  • ==WCD9378
  • ==SM6475Q
  • ==CQ8725S
  • ==FastConnect 6700
  • ==QXM1093
  • ==QXM1095
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==QXM1083
  • ==QXM1086
  • ==SM8735P
  • ==XRV7209
  • ==SM8845P
  • ==WSA8840
  • ==QXM1094
  • ==G2 Gen 1
  • ==WSA8810
  • ==SM7635P
  • ==Pandeiro
  • ==Qualcomm Video Collaboration VC3 Platform

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47408
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Untrusted Pointer Dereference in Power Optimization Firmware

Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

Affected products

Snapdragon
  • ==SD865 5G
  • ==WCD9385
  • ==WSA8845
  • ==Snapdragon XR2 5G Platform
  • ==IQX7181
  • ==QCA0000
  • ==SC8380XP
  • ==SM6250
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==FastConnect 7800
  • ==FastConnect 6900
  • ==FastConnect 6200
  • ==IQX5121
  • ==Snapdragon 7c Compute Platform
  • ==WSA8840
  • ==WSA8810
  • ==WSA8815
  • ==WCD9380
  • ==Snapdragon 7c Gen 2 Compute Platform "Rennell Pro"
  • ==WSA8845H

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-26332
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
vm2: Sandbox Escape

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.

Affected products

vm2
  • ==< 3.11.0

Matching in nixpkgs

pkgs.lvm2

Tools to support Logical Volume Management (LVM) on Linux

pkgs.lvm2_vdo

Tools to support Logical Volume Management (LVM) on Linux

Package maintainers

Dismissed
(not in Nixpkgs)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Dify Vulnerable to Stored XSS via SVG-file upload

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched in version 1.13.1.

Affected products

dify
  • ==< 1.13.1

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-42076
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Evolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code Execution

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to execSync() without proper sanitization, enabling remote code execution when the corpus parameter contains shell metacharacters. This issue has been patched in version 1.69.3.

Affected products

evolver
  • ==< 1.69.3

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47404
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Buffer Copy Without Checking Size of Input in Automotive Audio

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

Affected products

Snapdragon
  • ==QCA8081
  • ==SA8195P
  • ==Snapdragon X53 5G Modem-RF System
  • ==QCN6224
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==MDM9250
  • ==WCN6755
  • ==5G Fixed Wireless Access Platform
  • ==LeMansAU
  • ==Snapdragon X32 5G Modem-RF System
  • ==WCD9371
  • ==SA4155P
  • ==Snapdragon 662 Mobile Platform
  • ==WCN3615
  • ==SA8255P
  • ==QCA8695AU
  • ==QCA9377
  • ==QFW7124
  • ==QCA6174A
  • ==QRB5165M
  • ==SM7550
  • ==Snapdragon 865 5G Mobile Platform
  • ==SM7675
  • ==SA9000P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCS4290
  • ==WCD9395
  • ==QCA6584AU
  • ==Snapdragon 870 5G Mobile Platform
  • ==SA7255P
  • ==QCA6698AQ
  • ==SA6150P
  • ==QCN6274
  • ==QCN9011
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==CSRA6640
  • ==Snapdragon 778G 5G Mobile Platform
  • ==QCS6690
  • ==SXR2350P
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==SM7525
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==SM6225P
  • ==QAM8255P
  • ==QFW7114
  • ==Snapdragon X55 5G Modem-RF System
  • ==QCA9367
  • ==SM7550P
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FWA Gen 3 Ultra Platform
  • ==WCN6450
  • ==FastConnect 7800
  • ==QCM2290
  • ==SA2150P
  • ==WCN7881
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8155P
  • ==Smart Audio 400 Platform
  • ==AR8035
  • ==SRV1M
  • ==WCN3660B
  • ==QCA2066
  • ==WSA8815
  • ==QCA6696
  • ==SA8770P
  • ==WCD9380
  • ==QCM6125
  • ==SA8295P
  • ==Robotics RB2 Platform
  • ==WSA8845H
  • ==QCA6797AQ
  • ==WCD9335
  • ==C-V2X 9150
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==Milos_IOT
  • ==SnapdragonAuto 4GModem
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==SXR2250P
  • ==WCN3988
  • ==WCN7861
  • ==QCA6595
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==SM8635P
  • ==SM7325P
  • ==Snapdragon XR2 5G Platform
  • ==SA6155P
  • ==SW5100P
  • ==QCM6490
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9326
  • ==WCD9370
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==SA6145P
  • ==Snapdragon X12 LTE Modem
  • ==QCA6574
  • ==QCA6595AU
  • ==QCM4325
  • ==QAM8295P
  • ==Snapdragon 680 4G Mobile Platform
  • ==WSA8832
  • ==CSRA6620
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==QCS2290
  • ==SXR2230P
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==G3x Gen 2
  • ==WCD9360
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCA8337
  • ==QEP8111
  • ==SA4150P
  • ==QAMSRV1M
  • ==Robotics RB5 Platform
  • ==QCS8550
  • ==SA6155
  • ==SXR2330P
  • ==QAMSRV1H
  • ==SD865 5G
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==WCD9378
  • ==FastConnect 6800
  • ==FastConnect 6700
  • ==Snapdragon 782G Mobile Platform
  • ==QCA6574AU
  • ==SA8155
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==Qualcomm 215 Mobile Platform
  • ==MDM9628
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==SA7775P
  • ==SDA660
  • ==WCN3990
  • ==QCA6564A
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==WCD9341
  • ==Kalpeni
  • ==SM7675P
  • ==Snapdragon 660 Mobile Platform
  • ==WSA8810
  • ==SA8145P
  • ==QCA6564AU
  • ==SM7635P
  • ==Snapdragon 888 5G Mobile Platform
  • ==WCD9340
  • ==WCN3680B
  • ==Snapdragon Auto 5G Modem-RF
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SA8150P
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==AR8031
  • ==Snapdragon 4 Gen 1 Mobile Platform

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-26956
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
vm2: WASM Sandbox Escape (Node 25 only)

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.

Affected products

vm2
  • === 3.10.4

Matching in nixpkgs

pkgs.lvm2

Tools to support Logical Volume Management (LVM) on Linux

pkgs.lvm2_vdo

Tools to support Logical Volume Management (LVM) on Linux

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-24781
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
vm2: Sandbox Breakout Through Inspect

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.

Affected products

vm2
  • ==< 3.11.0

Matching in nixpkgs

pkgs.lvm2

Tools to support Logical Volume Management (LVM) on Linux

pkgs.lvm2_vdo

Tools to support Logical Volume Management (LVM) on Linux

Package maintainers