Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47401
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Buffer Over-read in WLAN HAL

Transient DOS when processing target power rate tables during channel configuration.

Affected products

Snapdragon
  • ==QCN9160
  • ==XRV9209
  • ==QCA8101
  • ==QCA8081
  • ==SA8195P
  • ==QCA8112
  • ==QCN6224
  • ==WSA8845
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==IPQ5302
  • ==QPA1083BD
  • ==SM6850
  • ==QCA8111
  • ==WCN6650
  • ==SM8650Q
  • ==SC8380XP
  • ==QCN5124
  • ==QCA2064
  • ==SM8550P
  • ==WCN6755
  • ==QCA2065
  • ==SM8750P
  • ==LeMansAU
  • ==QMB415
  • ==QMP1000
  • ==SM6450P
  • ==Snapdragon X32 5G Modem-RF System
  • ==WCD9371
  • ==QCN9000
  • ==QCF8001
  • ==IPQ5332
  • ==SA8255P
  • ==QCA8695AU
  • ==IQX5121
  • ==QFW7124
  • ==QCA6174A
  • ==QRB5165M
  • ==SD 8 Gen1 5G
  • ==SM7550
  • ==SM7675
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==QLN1086BD
  • ==SA9000P
  • ==QCA6777AQ
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCA6584AU
  • ==WCD9395
  • ==IQ9 Series Platform
  • ==QCA6698AQ
  • ==SA7255P
  • ==Molokai
  • ==QCN6274
  • ==QLN1083BD
  • ==Netrani
  • ==Marina
  • ==Networking Pro 810 Platform
  • ==QCN9011
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==QCA8385
  • ==Snapdragon X72 5G Modem-RF System
  • ==IPQ5312
  • ==IPQ9554
  • ==QCA6554A
  • ==SM7435P
  • ==QCS6690
  • ==SXR2350P
  • ==QCA6678AQ
  • ==Flight RB5 5G Platform
  • ==WCN7760
  • ==SM7525
  • ==Monaco_IOT
  • ==SA8620P
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==QXM1096
  • ==QXM8083
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==X2000077
  • ==QAM8255P
  • ==IQ8 Series Platform
  • ==QFW7114
  • ==QMP2001
  • ==QCA2062
  • ==QCN6422
  • ==Snapdragon 8 Elite
  • ==QCN6432
  • ==QPA1086BD
  • ==SM7550P
  • ==QRB5165N
  • ==X2000092
  • ==FWA Gen 3 Ultra Platform
  • ==WCN6450
  • ==FastConnect 7800
  • ==Immersive Home 3210 Platform
  • ==IPQ9008
  • ==Networking Pro 1200 Platform
  • ==WCN7881
  • ==SAR1165P
  • ==SM6475P
  • ==Snapdragon 8 Elite Gen 5
  • ==SA8155P
  • ==SM8475P
  • ==AR8035
  • ==QCA6696
  • ==QCA2066
  • ==QCF8000
  • ==WSA8815
  • ==SA8770P
  • ==SRV1M
  • ==WCD9380
  • ==Snapdragon X62 5G Modem-RF System
  • ==Orne
  • ==SA8295P
  • ==WSA8845H
  • ==QCA6797AQ
  • ==Snapdragon 7 Gen 4 Mobile Platform
  • ==WCN7860
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==Milos_IOT
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==Cologne
  • ==QCN5224
  • ==QCA8386
  • ==WCN3988
  • ==SXR2250P
  • ==WCN7861
  • ==XG101002
  • ==X1E80100
  • ==QCA6595
  • ==SM8635P
  • ==QCN9024
  • ==Palawan25
  • ==SDX61
  • ==SA6155P
  • ==QCM6490
  • ==WSA8850
  • ==QCA0000
  • ==QCA6391
  • ==Milos
  • ==QCN6412
  • ==QCA8084
  • ==QCS4490
  • ==Immersive Home 326 Platform
  • ==SRV1H
  • ==X2000094
  • ==SM6650P
  • ==WCD9370
  • ==Snapdragon AR1 Gen 1 Platform
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==Networking Pro 610 Platform
  • ==QCA6574
  • ==QCA6595AU
  • ==QAM8295P
  • ==WCD9378C
  • ==WSA8832
  • ==FastConnect 6900
  • ==XG101039
  • ==WCN7880
  • ==QCA8080
  • ==SXR2230P
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==G3x Gen 2
  • ==X2000090
  • ==SAR2130P
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==CQ7790
  • ==QCA8337
  • ==QEP8111
  • ==QCN9274
  • ==QCA8384
  • ==QAMSRV1M
  • ==QCN5154
  • ==SW-only
  • ==Robotics RB5 Platform
  • ==QCS8550
  • ==SXR2330P
  • ==QAMSRV1H
  • ==QAM8397P
  • ==Networking Pro 1210 Platform
  • ==WCD9385
  • ==QCA6688AQ
  • ==QMB715
  • ==IQ6 Series Platform
  • ==WSA8850W
  • ==QCA6787AQ
  • ==WSA8830
  • ==XG101032
  • ==IPQ9574
  • ==IQX7181
  • ==QCA6574A
  • ==WSA8855C
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==QCA8102
  • ==SM7435
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==WCD9378
  • ==QCN6402
  • ==IPQ9570
  • ==CQ8725S
  • ==FastConnect 6700
  • ==Networking Pro 1610 Platform
  • ==SM6475Q
  • ==QXM1093
  • ==QCA6574AU
  • ==QXM1095
  • ==X2000086
  • ==QXM1083
  • ==QXM1086
  • ==SM7425
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==Snapdragon X65 5G Modem-RF System
  • ==QCA8085
  • ==QCA8082
  • ==SM8735P
  • ==SM8425
  • ==XRV7209
  • ==SA7775P
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==QCN6024
  • ==SM8845P
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==QCA8075
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==QXM1094
  • ==CQ8750M
  • ==G2 Gen 1
  • ==SM7675P
  • ==WSA8810
  • ==IPQ5300
  • ==QCA6564AU
  • ==SM7635P
  • ==Snapdragon 888 5G Mobile Platform
  • ==WCD9340
  • ==SA510M
  • ==Pandeiro
  • ==Snapdragon Auto 5G Modem-RF
  • ==QCM4490
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47403
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Buffer Over-read in WLAN Firmware

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

Affected products

Snapdragon
  • ==XRV9209
  • ==QCA8081
  • ==QCN5024
  • ==QCN6224
  • ==WSA8845
  • ==IPQ5302
  • ==QPA1083BD
  • ==SM6850
  • ==WCN6650
  • ==SM8650Q
  • ==SC8380XP
  • ==QCN5124
  • ==SM8550P
  • ==Immersive Home 318 Platform
  • ==WCN6755
  • ==QCN5122
  • ==SM8750P
  • ==LeMansAU
  • ==QMB415
  • ==QMP1000
  • ==IPQ5028
  • ==SM6450P
  • ==WCD9371
  • ==QCN9000
  • ==QCF8001
  • ==IPQ5332
  • ==SA8255P
  • ==QCA8695AU
  • ==IQX5121
  • ==QCN5152
  • ==QFW7124
  • ==QCA6174A
  • ==SM7550
  • ==SD 8 Gen1 5G
  • ==SM7675
  • ==IPQ6010
  • ==QLN1086BD
  • ==SA9000P
  • ==QCA6777AQ
  • ==Immersive Home 316 Platform
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==QCA6584AU
  • ==QCC2073
  • ==QCN9001
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==WCD9395
  • ==SA7255P
  • ==QCA6698AQ
  • ==Molokai
  • ==QCN6274
  • ==QLN1083BD
  • ==Netrani
  • ==QCN5022
  • ==Marina
  • ==Networking Pro 810 Platform
  • ==QCN9011
  • ==QCN9012
  • ==QCN9022
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==IPQ5312
  • ==IPQ9554
  • ==QCA6554A
  • ==SM7435P
  • ==QCS6690
  • ==SXR2350P
  • ==QCA6678AQ
  • ==WCN7760
  • ==SM7525
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==QCA9889
  • ==QXM1096
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==QAM8255P
  • ==QFW7114
  • ==QMP2001
  • ==X2000077
  • ==Networking Pro 400 Platform
  • ==QCN6422
  • ==Snapdragon 8 Elite
  • ==QCN6432
  • ==QPA1086BD
  • ==SM7550P
  • ==FWA Gen 3 Ultra Platform
  • ==X2000092
  • ==FastConnect 7800
  • ==Immersive Home 3210 Platform
  • ==Networking Pro 1200 Platform
  • ==IPQ9008
  • ==SAR1165P
  • ==WCN6450
  • ==SM6475P
  • ==WCN7881
  • ==Snapdragon 8 Elite Gen 5
  • ==SM8475P
  • ==CSR8811
  • ==AR8035
  • ==QCA6696
  • ==QCF8000
  • ==SRV1M
  • ==SA8770P
  • ==WSA8815
  • ==WCD9380
  • ==Snapdragon X62 5G Modem-RF System
  • ==IPQ8076
  • ==Orne
  • ==QCA6797AQ
  • ==Snapdragon 7 Gen 4 Mobile Platform
  • ==WSA8845H
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==WCN7860
  • ==Milos_IOT
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==LeMans_AU_LGIT
  • ==QCA9888
  • ==FWA Gen 5 Elite Platform
  • ==WSA8835
  • ==Cologne
  • ==SDX65M
  • ==Networking Pro 600 Platform
  • ==QCA8386
  • ==SXR2250P
  • ==SM8635P
  • ==QCA6595
  • ==WCN3988
  • ==WCN7861
  • ==X1E80100
  • ==QCN9024
  • ==Palawan25
  • ==SDX61
  • ==XG101002
  • ==QCM6490
  • ==QCA6391
  • ==QCA0000
  • ==WSA8850
  • ==Milos
  • ==QCA4024
  • ==QCN5054
  • ==QCA8084
  • ==QCN6412
  • ==QCS4490
  • ==Immersive Home 326 Platform
  • ==SRV1H
  • ==X2000094
  • ==SM6650P
  • ==Networking Pro 800 Platform
  • ==Immersive Home 214 Platform
  • ==WCD9370
  • ==Snapdragon AR1 Gen 1 Platform
  • ==IPQ6000
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==Networking Pro 610 Platform
  • ==QCA6574
  • ==QCA6595AU
  • ==QCN6132
  • ==WCD9378C
  • ==QCC2076
  • ==WSA8832
  • ==FastConnect 6900
  • ==QCN9100
  • ==XG101039
  • ==WCN7880
  • ==QCA8080
  • ==SXR2230P
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==G3x Gen 2
  • ==X2000090
  • ==SAR2130P
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==CQ7790
  • ==QCA8337
  • ==QCN9274
  • ==QAMSRV1M
  • ==QCN5154
  • ==QCS8550
  • ==NPro A8 Elite Platform
  • ==QAMSRV1H
  • ==SXR2330P
  • ==QCN6122
  • ==QAM8397P
  • ==Networking Pro 1210 Platform
  • ==WCD9385
  • ==IPQ5010
  • ==QCA6688AQ
  • ==QMB715
  • ==QCA6787AQ
  • ==WSA8850W
  • ==WSA8830
  • ==IPQ9574
  • ==QCA6574A
  • ==IQX7181
  • ==XG101032
  • ==IPQ8078
  • ==SM8635
  • ==WSA8855C
  • ==WCD9390
  • ==WCD9375
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==SM7435
  • ==WCD9378
  • ==QCN6402
  • ==IPQ9570
  • ==CQ8725S
  • ==FastConnect 6700
  • ==Networking Pro 1610 Platform
  • ==QCN9002
  • ==QCN5164
  • ==QCA6574AU
  • ==QXM1093
  • ==SM6475Q
  • ==QCN9070
  • ==QXM1095
  • ==QCA8072
  • ==QCN6023
  • ==Trestles
  • ==QXM1083
  • ==QXM1086
  • ==SM7425
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==Snapdragon X65 5G Modem-RF System
  • ==X2000086
  • ==QCA8085
  • ==QCA8082
  • ==SM8735P
  • ==SM8425
  • ==SA7775P
  • ==XRV7209
  • ==QCN6024
  • ==QCN9003
  • ==SM8845P
  • ==IPQ6018
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==QCN5052
  • ==Immersive Home 216 Platform
  • ==QCA8075
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==QXM1094
  • ==CQ8750M
  • ==G2 Gen 1
  • ==SM7675P
  • ==WSA8810
  • ==IPQ5300
  • ==QCA6564AU
  • ==SM7635P
  • ==Kobuk
  • ==SDX81
  • ==WCD9340
  • ==Pandeiro
  • ==QCM4490
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==QCC710

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-42075
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enabling directory traversal attacks that can overwrite critical system files or create files in sensitive location. This issue has been patched in version 1.69.3.

Affected products

evolver
  • ==< 1.69.3

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-24118
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
VM2 Sandbox Breakout Through __lookupGetter__

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.

Affected products

vm2
  • ==< 3.11.0

Matching in nixpkgs

pkgs.lvm2

Tools to support Logical Volume Management (LVM) on Linux

pkgs.lvm2_vdo

Tools to support Logical Volume Management (LVM) on Linux

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-42077
5.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Evolver: Prototype Pollution via `Object.assign()` in mailbox store operations

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The vulnerability exists in the _applyUpdate() and _updateRecord() functions which use Object.assign() to merge user-controlled data without filtering dangerous keys like __proto__, constructor, or prototype. This issue has been patched in version 1.69.3.

Affected products

evolver
  • ==< 1.69.3

Matching in nixpkgs

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-25293
9.6 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Incorrect authorization in PLC FW

Buffer overflow due to incorrect authorization in PLC FW

Affected products

Snapdragon
  • ==QCA7005

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-24082
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Use After Free in Automotive GPU

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

Affected products

Snapdragon
  • ==XRV9209
  • ==QCA8081
  • ==SA8195P
  • ==QCN6224
  • ==WSA8845
  • ==Qualcomm Dragonwing QRU100 Platform
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==QPA1083BD
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==QDU1000
  • ==SM8550P
  • ==MDM9250
  • ==WCN6755
  • ==LeMansAU
  • ==Snapdragon X32 5G Modem-RF System
  • ==SA4155P
  • ==WCD9371
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==QCA8695AU
  • ==QCA9377
  • ==QFW7124
  • ==QCA6174A
  • ==QRB5165M
  • ==SM7550
  • ==SM7675
  • ==QLN1086BD
  • ==SA9000P
  • ==QCS4290
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==WCD9395
  • ==QCA6584AU
  • ==SA7255P
  • ==QCA6698AQ
  • ==SA6150P
  • ==QCN6274
  • ==QLN1083BD
  • ==QCN9011
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==CSRA6640
  • ==QCS6690
  • ==SXR2350P
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==SM7525
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==QXM1096
  • ==SM6225P
  • ==QAM8255P
  • ==QFW7114
  • ==QCA9367
  • ==QPA1086BD
  • ==SM7550P
  • ==QRB5165N
  • ==FWA Gen 3 Ultra Platform
  • ==QDX1010
  • ==FastConnect 7800
  • ==WCN6450
  • ==QCM2290
  • ==SAR1165P
  • ==WCN7881
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8155P
  • ==Smart Audio 400 Platform
  • ==AR8035
  • ==QCA6696
  • ==QCA2066
  • ==SRV1M
  • ==WSA8815
  • ==SA8770P
  • ==WCD9380
  • ==QDX1011
  • ==QRU1032
  • ==QCM6125
  • ==SA8295P
  • ==Robotics RB2 Platform
  • ==WSA8845H
  • ==QCA6797AQ
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==WCD9335
  • ==WCN7860
  • ==Milos_IOT
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==WCN7861
  • ==SA6155P
  • ==QCM6490
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9370
  • ==Snapdragon AR1 Gen 1 Platform
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==SA6145P
  • ==QCA6574
  • ==QCA6595AU
  • ==Qualcomm Dragonwing X100 Accelerator Card
  • ==QCM4325
  • ==QAM8295P
  • ==WSA8832
  • ==CSRA6620
  • ==QDU1110
  • ==Snapdragon 680 4G Mobile Platform
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==QCS2290
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==G3x Gen 2
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCA8337
  • ==QEP8111
  • ==SA4150P
  • ==QAMSRV1M
  • ==QDU1210
  • ==Robotics RB5 Platform
  • ==QCS8550
  • ==SXR2330P
  • ==QAMSRV1H
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==Snapdragon AR1+ Gen 1 Platform
  • ==WCD9378
  • ==FastConnect 6700
  • ==QXM1093
  • ==QCA6574AU
  • ==QXM1095
  • ==QXM1083
  • ==QXM1086
  • ==MDM9628
  • ==XRV7209
  • ==SA7775P
  • ==QCA6564A
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==QXM1094
  • ==Kalpeni
  • ==SM7675P
  • ==SA8145P
  • ==WSA8810
  • ==QCA6564AU
  • ==SM7635P
  • ==WCD9340
  • ==Pandeiro
  • ==Snapdragon Auto 5G Modem-RF
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SA8150P
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==AR8031
  • ==Snapdragon 4 Gen 1 Mobile Platform

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-47406
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Buffer Over-read in DSP Service

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

Affected products

Snapdragon
  • ==WSA8835
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==Cologne
  • ==WCD9385
  • ==Snapdragon 8cx Gen 3 Compute Platform
  • ==WSA8845
  • ==XG101002
  • ==QCM6490
  • ==WSA8830
  • ==XG101032
  • ==IQX7181
  • ==QCA0000
  • ==SC8380XP
  • ==WCD9375
  • ==X2000077
  • ==FastConnect 6700
  • ==X2000094
  • ==WCD9370
  • ==X2000086
  • ==WCD9378C
  • ==X2000092
  • ==FastConnect 7800
  • ==FastConnect 6900
  • ==XG101039
  • ==QCM5430
  • ==IQX5121
  • ==WSA8840
  • ==X2000090
  • ==WCD9380
  • ==WSA8845H
  • ==Qualcomm Video Collaboration VC3 Platform

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-42092
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Global Settings Publication Exposes Sensitive Configuration to Any Authenticated User in Titra

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and google_clientid. At time of publication no public patch is available.

Affected products

titra
  • === 0.99.52

Matching in nixpkgs

Dismissed
(not in Nixpkgs)
Permalink CVE-2025-42611
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Improper certificate validation in multiple RouterOS services

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses the system certificate store that is shared and equally trusted by all system services. This causes confusion of scope, allowing any certificate authority present in the system-wide trust store to be trusted in any context (with some exceptions), allowing partial or full authentication bypass in CAPsMAN, OpenVPN, Dot1X and potentially others.

References

Affected products

RouterOS
  • =<7.20.x

Matching in nixpkgs

Package maintainers