CRITICAL
Nix affected by unsafe NAR unpacking
Published Sep 10, 2024
9.1
CRITICALCVSS 3.1
EPSS 0.60%
Description
Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be with root permissions when using the Nix daemon. This issue is fixed in Nix 2.24.6.
Affected products
-
- Version >= 2.24.0, < 2.24.6StatusaffectedConstraints-
- Version
-
- Version 2.24.0StatusaffectedConstraints<2.24.6
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-41529 Advisory
- https://github.com/NixOS/nix/commit/eb11c1499876cd4c9c188cbda5b1003b36ce2e59 x_refsource_MISCPatch
- https://github.com/NixOS/nix/security/advisories/GHSA-h4vv-h3jq-v493 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-41529 | Advisory | |
| https://github.com/NixOS/nix/commit/eb11c1499876cd4c9c188cbda5b1003b36ce2e59 | x_refsource_MISCPatch | |
| https://github.com/NixOS/nix/security/advisories/GHSA-h4vv-h3jq-v493 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 10, 2024
Updated Sep 10, 2024
Reserved Sep 2, 2024
Link CVE-2024-45593
CISA Vulnrichment
Updated Sep 10, 2024
ENISA EUVD
EUVD-2024-41529 Assigner GitHub_M
Published Sep 10, 2024
Updated Sep 10, 2024
Exploited since n/a
Link EUVD-2024-41529