Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2026-3392
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    20 packages
    • lilypond
    • lilypond-unstable
    • lilypond-with-fonts
    • openlilylib-fonts.ross
    • gnomeExtensions.lilypad
    • openlilylib-fonts.haydn
    • openlilylib-fonts.bravura
    • openlilylib-fonts.cadence
    • openlilylib-fonts.gonville
    • openlilylib-fonts.lilyjazz
    • openlilylib-fonts.paganini
    • openlilylib-fonts.profondo
    • openlilylib-fonts.beethoven
    • openlilylib-fonts.improviso
    • openlilylib-fonts.scorlatti
    • lilypond-unstable-with-fonts
    • openlilylib-fonts.lilyboulez
    • openlilylib-fonts.sebastiano
    • openlilylib-fonts.lv-goldenage
    • openlilylib-fonts.gutenberg1939
  • @LeSuisse dismissed
FascinatedBox lily lily_emitter.c eval_tree null pointer dereference

A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

lily
  • ==2.2
  • ==2.0
  • ==2.3
  • ==2.1
Ignored packages (20)
Not present in nixpkgs
Permalink CVE-2026-3385
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • fairywren
    • tree-sitter-grammars.tree-sitter-wren
    • python313Packages.tree-sitter-grammars.tree-sitter-wren
    • python314Packages.tree-sitter-grammars.tree-sitter-wren
  • @LeSuisse dismissed
wren-lang wren wren_compiler.c resolveLocal recursion

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

wren
  • ==0.3
  • ==0.1
  • ==0.2
  • ==0.4.0
Ignored packages (4)
Not present in nixpkgs
Permalink CVE-2026-3386
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • fairywren
    • tree-sitter-grammars.tree-sitter-wren
    • python313Packages.tree-sitter-grammars.tree-sitter-wren
    • python314Packages.tree-sitter-grammars.tree-sitter-wren
  • @LeSuisse dismissed
wren-lang wren wren_compiler.c emitOp out-of-bounds

A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

wren
  • ==0.3
  • ==0.1
  • ==0.2
  • ==0.4.0
Ignored packages (4)
Not present in nixpkgs
Permalink CVE-2026-3387
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • fairywren
    • tree-sitter-grammars.tree-sitter-wren
    • python313Packages.tree-sitter-grammars.tree-sitter-wren
    • python314Packages.tree-sitter-grammars.tree-sitter-wren
  • @LeSuisse dismissed
wren-lang wren wren_compiler.c getByteCountForArguments null pointer dereference

A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

wren
  • ==0.3
  • ==0.1
  • ==0.2
  • ==0.4.0
Ignored packages (4)
Not present in nixpkgs
Permalink CVE-2026-3391
3.3 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Not Defined (X)
  • Report Confidence (RC): Reasonable (R)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    20 packages
    • lilypond
    • lilypond-unstable
    • lilypond-with-fonts
    • openlilylib-fonts.ross
    • gnomeExtensions.lilypad
    • openlilylib-fonts.haydn
    • openlilylib-fonts.bravura
    • openlilylib-fonts.cadence
    • openlilylib-fonts.gonville
    • openlilylib-fonts.lilyjazz
    • openlilylib-fonts.paganini
    • openlilylib-fonts.profondo
    • openlilylib-fonts.beethoven
    • openlilylib-fonts.improviso
    • openlilylib-fonts.scorlatti
    • lilypond-unstable-with-fonts
    • openlilylib-fonts.lilyboulez
    • openlilylib-fonts.sebastiano
    • openlilylib-fonts.lv-goldenage
    • openlilylib-fonts.gutenberg1939
  • @LeSuisse dismissed
FascinatedBox lily lily_emitter.c clear_storages out-of-bounds

A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

lily
  • ==2.2
  • ==2.0
  • ==2.3
  • ==2.1
Ignored packages (20)
Not present in nixpkgs
Permalink CVE-2025-47379
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Use After Free in Automotive Audio

Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.

Affected products

Snapdragon
  • ==QCA8081
  • ==SA8195P
  • ==Snapdragon X53 5G Modem-RF System
  • ==QCN6224
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==MDM9250
  • ==WCN6755
  • ==5G Fixed Wireless Access Platform
  • ==LeMansAU
  • ==Snapdragon X32 5G Modem-RF System
  • ==SA4155P
  • ==WCD9371
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==WCN3615
  • ==QCA8695AU
  • ==QCA9377
  • ==QFW7124
  • ==QCA6174A
  • ==QRB5165M
  • ==SM7550
  • ==Snapdragon 865 5G Mobile Platform
  • ==SM7675
  • ==SA9000P
  • ==QCA6564
  • ==QCS4290
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==WCD9395
  • ==QCA6584AU
  • ==Snapdragon 870 5G Mobile Platform
  • ==SA7255P
  • ==QCA6698AQ
  • ==SA6150P
  • ==QCN6274
  • ==QCN9011
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==CSRA6640
  • ==Snapdragon 778G 5G Mobile Platform
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==SM6225P
  • ==QAM8255P
  • ==QFW7114
  • ==Snapdragon X55 5G Modem-RF System
  • ==QCA9367
  • ==SM7550P
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FWA Gen 3 Ultra Platform
  • ==FastConnect 7800
  • ==SA2150P
  • ==QCM2290
  • ==WCN6450
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8155P
  • ==Smart Audio 400 Platform
  • ==AR8035
  • ==QCA6696
  • ==QCA2066
  • ==SRV1M
  • ==SA8770P
  • ==WCN3660B
  • ==WSA8815
  • ==WCD9380
  • ==QCM6125
  • ==SA8295P
  • ==Robotics RB2 Platform
  • ==QCA6797AQ
  • ==WSA8845H
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==C-V2X 9150
  • ==Snapdragon 690 5G Mobile Platform
  • ==WCD9335
  • ==LeMans_AU_LGIT
  • ==SnapdragonAuto 4GModem
  • ==WSA8835
  • ==WCN3980
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==SM7325P
  • ==Snapdragon XR2 5G Platform
  • ==SA6155P
  • ==QCM6490
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9326
  • ==WCD9370
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==SA6145P
  • ==QCA6574
  • ==QCA6595AU
  • ==Snapdragon X12 LTE Modem
  • ==QCM4325
  • ==QAM8295P
  • ==Snapdragon 680 4G Mobile Platform
  • ==CSRA6620
  • ==WSA8832
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==QCS2290
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==WCD9360
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCA8337
  • ==QEP8111
  • ==SA4150P
  • ==QAMSRV1M
  • ==Robotics RB5 Platform
  • ==SA6155
  • ==QCS8550
  • ==QAMSRV1H
  • ==SD865 5G
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==WCD9378
  • ==FastConnect 6800
  • ==FastConnect 6700
  • ==Snapdragon 782G Mobile Platform
  • ==QCA6574AU
  • ==SA8155
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==Qualcomm 215 Mobile Platform
  • ==MDM9628
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==SA7775P
  • ==SDA660
  • ==WCN3990
  • ==QCA6564A
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==WCD9341
  • ==SM7675P
  • ==Snapdragon 660 Mobile Platform
  • ==SA8145P
  • ==WSA8810
  • ==QCA6564AU
  • ==SM7635P
  • ==Snapdragon 888 5G Mobile Platform
  • ==WCD9340
  • ==WCN3680B
  • ==Snapdragon Auto 5G Modem-RF
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SA8150P
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==AR8031
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47383
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Missing Cryptographic Step in Data Modem

Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

Affected products

Snapdragon
  • ==Snapdragon X80 5G Modem-RF System
  • ==QCA8081
  • ==Snapdragon X53 5G Modem-RF System
  • ==QCN6224
  • ==WSA8845
  • ==Snapdragon 8c Compute Platform "Poipu Lite"
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==MDM9250
  • ==WCN6755
  • ==SM6250
  • ==5G Fixed Wireless Access Platform
  • ==CSRB31024
  • ==SM8750P
  • ==QMP1000
  • ==Snapdragon 820Am
  • ==WCD9371
  • ==Snapdragon X32 5G Modem-RF System
  • ==Snapdragon 8cx Compute Platform
  • ==Snapdragon 662 Mobile Platform
  • ==WCN3615
  • ==QCA9377
  • ==SD626
  • ==SW6100
  • ==Snapdragon X70 Modem-RF System
  • ==QFW7124
  • ==Snapdragon 429 Mobile Platform
  • ==QCA6174A
  • ==SM7550
  • ==SD 8 Gen1 5G
  • ==Snapdragon 865 5G Mobile Platform
  • ==SM7675
  • ==Snapdragon 6 Gen 3 Mobile Platform
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCS4290
  • ==Snapdragon 4 Gen 2 Mobile Platform
  • ==WCD9395
  • ==QCA6584AU
  • ==Vision Intelligence 400 Platform
  • ==Snapdragon 870 5G Mobile Platform
  • ==QCA6698AQ
  • ==SDX57M
  • ==QCN6274
  • ==Netrani
  • ==QCN9011
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==Smart Display 200 Platform
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==CSRA6640
  • ==Snapdragon 778G 5G Mobile Platform
  • ==SDX71M
  • ==Themisto
  • ==QCA6678AQ
  • ==SW5100
  • ==Snapdragon 8cx Compute Platform "Poipu Pro"
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==MDM9640
  • ==SM6225P
  • ==Snapdragon 7 Gen 1 Mobile Platform
  • ==Snapdragon 1200 Wearable Platform
  • ==QFW7114
  • ==9207 LTE Modem
  • ==Snapdragon 8 Elite
  • ==Snapdragon X55 5G Modem-RF System
  • ==QCA9367
  • ==WCD9330
  • ==SW6100P
  • ==SM7550P
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FWA Gen 3 Ultra Platform
  • ==WCD9306
  • ==FastConnect 7800
  • ==QCM2290
  • ==WCN7881
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==Vision Intelligence 100 Platform
  • ==Snapdragon X5 LTE Modem
  • ==SM8475P
  • ==AR8035
  • ==SDM429W
  • ==QCA6696
  • ==WCN3660B
  • ==WSA8815
  • ==WCD9380
  • ==Snapdragon 7c Gen 2 Compute Platform "Rennell Pro"
  • ==QCM6125
  • ==Orne
  • ==Robotics RB2 Platform
  • ==WSA8845H
  • ==QCA6797AQ
  • ==WCN7860
  • ==WCD9335
  • ==C-V2X 9150
  • ==Snapdragon 6 Gen 1 Mobile Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==SnapdragonAuto 4GModem
  • ==WSA8835
  • ==WCN3980
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCN3988
  • ==WCN7861
  • ==SM8635P
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==QCN9024
  • ==Palawan25
  • ==APQ8098
  • ==SDX61
  • ==SW5100P
  • ==QCM6490
  • ==SM7325P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==QCS4490
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SM6650P
  • ==WCD9326
  • ==WCD9370
  • ==AQT1000
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==Snapdragon 8cx Gen 2 5G Compute Platform
  • ==QCA6574
  • ==QCA6595AU
  • ==Snapdragon X12 LTE Modem
  • ==QCA6584
  • ==WCN3620
  • ==QCM4325
  • ==Snapdragon 626 Mobile Platform
  • ==WSA8832
  • ==CSRA6620
  • ==Snapdragon 680 4G Mobile Platform
  • ==FastConnect 6900
  • ==Snapdragon 8cx Gen 2 5G Compute Platform "Poipu Pro"
  • ==QCA6698AU
  • ==Snapdragon 8c Compute Platform (SC8180XP-AD) "Poipu Lite"
  • ==WCN7880
  • ==QCS2290
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==Snapdragon 7c Compute Platform
  • ==WCD9360
  • ==QCA6430
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==Snapdragon 625 Mobile Platform
  • ==QCA8337
  • ==QEP8111
  • ==Snapdragon 820 Automotive Platform
  • ==QCS8550
  • ==WCN3910
  • ==WCD9385
  • ==QCA6420
  • ==QCA6688AQ
  • ==Snapdragon 1100 Wearable Platform
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==SM7435
  • ==WCD9378
  • ==FastConnect 6800
  • ==FastConnect 6700
  • ==Snapdragon 782G Mobile Platform
  • ==QCA6574AU
  • ==9206 LTE Modem
  • ==Vision Intelligence 200 Platform
  • ==MDM8207
  • ==Snapdragon 7+ Gen 2 Mobile Platform
  • ==Qualcomm 215 Mobile Platform
  • ==Snapdragon X65 5G Modem-RF System
  • ==MDM9628
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==QCN6024
  • ==SDA660
  • ==WCN3990
  • ==Snapdragon 8+ Gen 1 Mobile Platform
  • ==QCA6564A
  • ==Snapdragon 8 Gen 1 Mobile Platform
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==FSM100 Platform
  • ==WCD9341
  • ==SM7675P
  • ==Snapdragon 660 Mobile Platform
  • ==WSA8810
  • ==QCA6564AU
  • ==SM7635P
  • ==Snapdragon 888 5G Mobile Platform
  • ==WCD9340
  • ==WCN3680B
  • ==Snapdragon Auto 5G Modem-RF
  • ==QCM4490
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47381
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Use After Free in Automotive Audio

Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.

Affected products

Snapdragon
  • ==QAMSRV1H
  • ==SA8195P
  • ==QCA6595
  • ==QCA6688AQ
  • ==SA6155P
  • ==QCA6574A
  • ==SA8620P
  • ==QAM8255P
  • ==SRV1H
  • ==QCA6574AU
  • ==QCA9367
  • ==LeMansAU
  • ==QCA6574
  • ==QCA6595AU
  • ==SA7775P
  • ==SA8255P
  • ==SA8155P
  • ==QCA9377
  • ==QCA6696
  • ==SRV1M
  • ==SA8770P
  • ==SA9000P
  • ==QAMSRV1M
  • ==SA7255P
  • ==LeMans_AU_LGIT
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47377
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Use After Free in Automotive Audio

Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.

Affected products

Snapdragon
  • ==QCA8081
  • ==SA8195P
  • ==QCN6224
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==WCN6755
  • ==LeMansAU
  • ==Snapdragon X32 5G Modem-RF System
  • ==WCD9371
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==QCA8695AU
  • ==QCA9377
  • ==QFW7124
  • ==QCA6174A
  • ==SM7550
  • ==SM7675
  • ==SA9000P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCS4290
  • ==WCD9395
  • ==QCA6584AU
  • ==SA7255P
  • ==QCA6698AQ
  • ==QCN6274
  • ==QCN9011
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==SXR2350P
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==SM6225P
  • ==QAM8255P
  • ==QFW7114
  • ==QCA9367
  • ==SM7550P
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FWA Gen 3 Ultra Platform
  • ==FastConnect 7800
  • ==WCN6450
  • ==QCM2290
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8155P
  • ==AR8035
  • ==QCA6696
  • ==SRV1M
  • ==SA8770P
  • ==WSA8815
  • ==WCD9380
  • ==QCM6125
  • ==SA8295P
  • ==QCA6797AQ
  • ==WSA8845H
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==SA6155P
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9370
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==QCA6574
  • ==QCA6595AU
  • ==QCM4325
  • ==QAM8295P
  • ==Snapdragon 680 4G Mobile Platform
  • ==WSA8832
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==QCS2290
  • ==FastConnect 6200
  • ==WCN3950
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCA8337
  • ==QEP8111
  • ==QAMSRV1M
  • ==Robotics RB5 Platform
  • ==QCS8550
  • ==SXR2330P
  • ==QAMSRV1H
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==WCD9378
  • ==QCA6574AU
  • ==SA7775P
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==SM7675P
  • ==WSA8810
  • ==SM7635P
  • ==WCD9340
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs
Permalink CVE-2025-47375
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 4 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package snapdragon-profiler
  • @LeSuisse dismissed
Use After Free in Automotive Audio

Memory corruption while handling different IOCTL calls from the user-space simultaneously.

Affected products

Snapdragon
  • ==QCA8081
  • ==SA8195P
  • ==Snapdragon X53 5G Modem-RF System
  • ==QCN6224
  • ==WSA8845
  • ==Qualcomm Video Collaboration VC5 Platform
  • ==WCN6650
  • ==SM8650Q
  • ==Snapdragon 480 5G Mobile Platform
  • ==SM8550P
  • ==MDM9250
  • ==WCN6755
  • ==LeMansAU
  • ==Snapdragon X32 5G Modem-RF System
  • ==SA4155P
  • ==WCD9371
  • ==Snapdragon 662 Mobile Platform
  • ==SA8255P
  • ==WCN3615
  • ==QCA8695AU
  • ==QCA9377
  • ==QFW7124
  • ==QCA6174A
  • ==QRB5165M
  • ==SM7550
  • ==Snapdragon 865 5G Mobile Platform
  • ==SM7675
  • ==SA9000P
  • ==Snapdragon 6 Gen 4 Mobile Platform
  • ==QCS4290
  • ==WCD9395
  • ==QCA6584AU
  • ==Snapdragon 870 5G Mobile Platform
  • ==SA7255P
  • ==QCA6698AQ
  • ==SA6150P
  • ==QCN6274
  • ==QCN9011
  • ==Snapdragon 778G+ 5G Mobile Platform
  • ==QCN9012
  • ==Snapdragon 8 Gen 3 Mobile Platform
  • ==Snapdragon X72 5G Modem-RF System
  • ==CSRA6640
  • ==Snapdragon 778G 5G Mobile Platform
  • ==QCA6678AQ
  • ==SW5100
  • ==Flight RB5 5G Platform
  • ==Snapdragon Auto 5G Modem-RF Gen 2
  • ==SA8620P
  • ==SM6225P
  • ==QAM8255P
  • ==QFW7114
  • ==Snapdragon X55 5G Modem-RF System
  • ==QCA9367
  • ==SM7550P
  • ==QRB5165N
  • ==Snapdragon W5+ Gen 1 Wearable Platform
  • ==FWA Gen 3 Ultra Platform
  • ==FastConnect 7800
  • ==WCN6450
  • ==QCM2290
  • ==G1 Gen 1
  • ==Qualcomm Video Collaboration VC1 Platform
  • ==SA8155P
  • ==Smart Audio 400 Platform
  • ==AR8035
  • ==QCA6696
  • ==QCA2066
  • ==SRV1M
  • ==SA8770P
  • ==WCN3660B
  • ==WSA8815
  • ==WCD9380
  • ==QCM6125
  • ==SA8295P
  • ==Robotics RB2 Platform
  • ==QCA6797AQ
  • ==WSA8845H
  • ==Snapdragon 8 Gen 2 Mobile Platform
  • ==Snapdragon 690 5G Mobile Platform
  • ==WCD9335
  • ==LeMans_AU_LGIT
  • ==WSA8835
  • ==WCN3980
  • ==Snapdragon 7c+ Gen 3 Compute
  • ==WCN3988
  • ==SM8635P
  • ==QCA6595
  • ==Snapdragon 865+ 5G Mobile Platform
  • ==SM7325P
  • ==Snapdragon XR2 5G Platform
  • ==SA6155P
  • ==QCM6490
  • ==SW5100P
  • ==QCA6391
  • ==Snapdragon 460 Mobile Platform
  • ==Milos
  • ==Snapdragon 480+ 5G Mobile Platform
  • ==Snapdragon 695 5G Mobile Platform
  • ==Snapdragon 685 4G Mobile Platform
  • ==SRV1H
  • ==SM6650P
  • ==WCD9326
  • ==WCD9370
  • ==Snapdragon 7s Gen 3 Mobile Platform
  • ==SA6145P
  • ==QCA6574
  • ==QCA6595AU
  • ==Snapdragon X12 LTE Modem
  • ==QCM4325
  • ==QAM8295P
  • ==Snapdragon 680 4G Mobile Platform
  • ==CSRA6620
  • ==WSA8832
  • ==FastConnect 6900
  • ==QCA6698AU
  • ==QCS2290
  • ==FastConnect 6200
  • ==QCM5430
  • ==WCN3950
  • ==Snapdragon 8+ Gen 2 Mobile Platform
  • ==QCA8337
  • ==QEP8111
  • ==SA4150P
  • ==QAMSRV1M
  • ==Robotics RB5 Platform
  • ==QAMSRV1H
  • ==SD865 5G
  • ==WCN3910
  • ==WCD9385
  • ==QCA6688AQ
  • ==WSA8830
  • ==QCA6574A
  • ==SD662
  • ==SM8635
  • ==WCD9390
  • ==WCD9375
  • ==WCD9378
  • ==FastConnect 6800
  • ==FastConnect 6700
  • ==Snapdragon 782G Mobile Platform
  • ==QCA6574AU
  • ==Snapdragon XR2+ Gen 1 Platform
  • ==Qualcomm 215 Mobile Platform
  • ==MDM9628
  • ==Snapdragon 888+ 5G Mobile Platform
  • ==SA7775P
  • ==SDA660
  • ==WCN3990
  • ==QCA6564A
  • ==Snapdragon X75 5G Modem-RF System
  • ==WSA8840
  • ==WCD9341
  • ==SM7675P
  • ==Snapdragon 660 Mobile Platform
  • ==SA8145P
  • ==WSA8810
  • ==QCA6564AU
  • ==SM7635P
  • ==Snapdragon 888 5G Mobile Platform
  • ==WCD9340
  • ==WCN3680B
  • ==Snapdragon Auto 5G Modem-RF
  • ==Qualcomm Video Collaboration VC3 Platform
  • ==SA8150P
  • ==Snapdragon X35 5G Modem-RF System
  • ==QCC710
  • ==AR8031
  • ==Snapdragon 4 Gen 1 Mobile Platform
Ignored packages (1)
Not present in nixpkgs