Nixos

Nix

9 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Published 14.07.2025 20:42:12
  • Last modified 15.07.2025 13:14:24

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.

  • EPSS 0.02%
  • Published 27.06.2025 00:00:00
  • Last modified 30.06.2025 18:38:48

A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

  • EPSS 0.02%
  • Published 27.06.2025 00:00:00
  • Last modified 30.06.2025 18:38:48

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2....

  • EPSS 0.02%
  • Published 27.06.2025 00:00:00
  • Last modified 30.06.2025 18:38:48

The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentia...

  • EPSS 0.01%
  • Published 27.06.2025 00:00:00
  • Last modified 30.06.2025 18:38:48

The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4,...

  • EPSS 0.02%
  • Published 27.06.2025 00:00:00
  • Last modified 30.06.2025 18:38:48

A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before ...

  • EPSS 0.04%
  • Published 31.10.2024 17:15:13
  • Last modified 01.11.2024 12:57:03

Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, exposed to users with `import <nix/fetchurl.nix>`) were not executed in the macOS sandbox. Thus, these builders (which are running und...

  • EPSS 0.06%
  • Published 26.09.2024 18:15:10
  • Last modified 30.09.2024 12:46:20

Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not verify TLS certificates on HTTPS connections. This could lead to connection details such as full...

  • EPSS 0.02%
  • Published 28.06.2024 14:15:03
  • Last modified 21.11.2024 09:26:13

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally acces...