Nixos

Nix

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 14.07.2025 20:42:12
  • Zuletzt bearbeitet 15.07.2025 13:14:24

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.

  • EPSS 0.02%
  • Veröffentlicht 27.06.2025 00:00:00
  • Zuletzt bearbeitet 30.06.2025 18:38:48

A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

  • EPSS 0.02%
  • Veröffentlicht 27.06.2025 00:00:00
  • Zuletzt bearbeitet 30.06.2025 18:38:48

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2....

  • EPSS 0.02%
  • Veröffentlicht 27.06.2025 00:00:00
  • Zuletzt bearbeitet 30.06.2025 18:38:48

The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentia...

  • EPSS 0.01%
  • Veröffentlicht 27.06.2025 00:00:00
  • Zuletzt bearbeitet 30.06.2025 18:38:48

The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4,...

  • EPSS 0.02%
  • Veröffentlicht 27.06.2025 00:00:00
  • Zuletzt bearbeitet 30.06.2025 18:38:48

A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before ...

  • EPSS 0.04%
  • Veröffentlicht 31.10.2024 17:15:13
  • Zuletzt bearbeitet 01.11.2024 12:57:03

Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, exposed to users with `import <nix/fetchurl.nix>`) were not executed in the macOS sandbox. Thus, these builders (which are running und...

  • EPSS 0.06%
  • Veröffentlicht 26.09.2024 18:15:10
  • Zuletzt bearbeitet 30.09.2024 12:46:20

Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not verify TLS certificates on HTTPS connections. This could lead to connection details such as full...

  • EPSS 0.02%
  • Veröffentlicht 28.06.2024 14:15:03
  • Zuletzt bearbeitet 21.11.2024 09:26:13

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally acces...