A critical security vulnerability (CVE-2026-39860) in Nix versions 2.21 through 2.34 allows privilege escalation via symlink attacks during fixed-output derivation registration, enabling arbitrary file writes as root. The issue affects default NixOS configurations and sandboxed Linux systems, with patches available in versions 2.28.6 through 2.34.5. This vulnerability was introduced as part of prior fixes for CVE-2024-27297.
Background
Nix is a popular package manager and build system known for its reproducible builds and sandboxed execution environments. Security vulnerabilities in build systems can have widespread impact due to their privileged access to system resources.
- Source
- Lobsters
- Published
- Apr 8, 2026 at 06:41 AM
- Score
- 8.0 / 10