Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the build chroot. A symlink, pointing to an arbitrary location in the filesystem, could be created by the derivation builder at that path. During output registration, the Nix process (running in the host mount namespace) would follow that symlink and overwrite the destination with the derivation's output contents. In multi-user installations, this allows all users able to submit builds to the Nix daemon (allowed-users - defaulting to all users) to gain root privileges by modifying sensitive files. This vulnerability is fixed in 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, and 2.28.6.
The temporary output file used during copying of derivation output was located inside the build chroot. The derivation builder could create a symlink at this location pointing to any location in the file system. When the Nix process running in the host mount namespace registered the output, it followed the symlink and overwrote the target with the contents of the derivation output. This way an attacker could modify any file writable by the Nix daemon, including sensitive system files.
A user with access to the Nix daemon (by default all system users) can obtain root privileges by modifying sensitive system files. The vulnerability affects only sandboxed builds on Linux — builds on macOS are not affected.
Update Nix to version 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, or 2.28.6 (depending on the branch in use). Patches are available in the NixOS/nix GitHub repository (commits 244f3ee, 4bc5a35, 7794354, a3163b9).
NixOS Nix in versions prior to: 2.28.6, 2.29.3, 2.30.4, 2.31.4, 2.32.7, 2.33.4, and 2.34.5 — only sandboxed installations on Linux in multi-user mode with the Nix daemon running as root.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:NLinux Kernel
OSLinuxall versionsNixos Nix
APPNixos2.19.4 – 2.19.72.20.5 – 2.20.92.21.0 – 2.28.6 (excl.)2.29.0 – 2.29.3 (excl.)2.18.2 – 2.18.92.31.0 – 2.31.4 (excl.)2.32.0 – 2.32.7 (excl.)2.33.0 – 2.33.4 (excl.)2.34.0 – 2.34.5 (excl.)2.30.0 – 2.30.4 (excl.)
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
RCE przez YAML deserialization w IBM Aspera Faspex
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
Command Injection w VMware Workspace One Access i Identity Manager