CRITICAL🇵🇱 Wersja polska

CVE-2026-39860

CVSS 9.0v3.1pub. 2026-04-08upd. 2026-07-24

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the build chroot. A symlink, pointing to an arbitrary location in the filesystem, could be created by the derivation builder at that path. During output registration, the Nix process (running in the host mount namespace) would follow that symlink and overwrite the destination with the derivation's output contents. In multi-user installations, this allows all users able to submit builds to the Nix daemon (allowed-users - defaulting to all users) to gain root privileges by modifying sensitive files. This vulnerability is fixed in 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, and 2.28.6.

🤖 AI Analysis
How it works

The temporary output file used during copying of derivation output was located inside the build chroot. The derivation builder could create a symlink at this location pointing to any location in the file system. When the Nix process running in the host mount namespace registered the output, it followed the symlink and overwrote the target with the contents of the derivation output. This way an attacker could modify any file writable by the Nix daemon, including sensitive system files.

Impact

A user with access to the Nix daemon (by default all system users) can obtain root privileges by modifying sensitive system files. The vulnerability affects only sandboxed builds on Linux — builds on macOS are not affected.

Mitigation & patch

Update Nix to version 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, or 2.28.6 (depending on the branch in use). Patches are available in the NixOS/nix GitHub repository (commits 244f3ee, 4bc5a35, 7794354, a3163b9).

Who is affected

NixOS Nix in versions prior to: 2.28.6, 2.29.3, 2.30.4, 2.31.4, 2.32.7, 2.33.4, and 2.34.5 — only sandboxed installations on Linux in multi-user mode with the Nix daemon running as root.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
  • Linux Kernel

    OS
    Linux
    all versions
  • Nixos Nix

    APP
    Nixos
    2.19.4 – 2.19.72.20.5 – 2.20.92.21.0 – 2.28.6 (excl.)2.29.0 – 2.29.3 (excl.)2.18.2 – 2.18.92.31.0 – 2.31.4 (excl.)2.32.0 – 2.32.7 (excl.)2.33.0 – 2.33.4 (excl.)2.34.0 – 2.34.5 (excl.)2.30.0 – 2.30.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex

CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product

RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection

CVE-2020-4006CRITICAL9.1⚠ KEVPL ✓same product

Command Injection w VMware Workspace One Access i Identity Manager