CVE Explorer
CVE-2026-39860
Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the bui
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nix","vendor":"NixOS","versions":[{"status":"affected","version":">= 2.21, < 2.28.6"},{"status":"affected","version":">= 2.29.0, < 2.29.3"},{"status":"affected","version":">= 2.30.0, < 2.30.4"},{"status":"affected","version":">= 2.31.0, < 2.31.4"},{"status":"affected","version":">= 2.32.0, < 2.32.7"},{"status":"affected","version":">= 2.33.0, < 2.33.4"},{"status":"affected","version":">= 2.34.0, < 2.34.5"},{"status":"affected","version":">= 2.20.5, <= 2.20.9"},{"status":"affected","version":">= 2.19.4, <= 2.19.7"},{"status":"affected","version":">= 2.18.2, <= 2.18.9"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-61","description":"CWE-61: UNIX Symbolic Link (Symlink) Following","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/problemTypes/0/descriptions/0
Source references
6 source assertions{"name":"https://github.com/NixOS/nix/commit/244f3eee0bbc7f11e9b383a15ed7368e2c4becc9","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nix/commit/244f3eee0bbc7f11e9b383a15ed7368e2c4becc9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/references/2
{"name":"https://github.com/NixOS/nix/commit/4bc5a3510fa3735798f9ed3a2a30a3ea7b32343a","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nix/commit/4bc5a3510fa3735798f9ed3a2a30a3ea7b32343a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/references/3
{"name":"https://github.com/NixOS/nix/commit/7794354a982449927ee7401cdeb573ddd16c4688","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nix/commit/7794354a982449927ee7401cdeb573ddd16c4688"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/references/4
{"name":"https://github.com/NixOS/nix/commit/a3163b9eabb952b4aa96e376dea95ebcca97b31a","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nix/commit/a3163b9eabb952b4aa96e376dea95ebcca97b31a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/references/5
{"name":"https://github.com/NixOS/nix/pull/10178","tags":["x_refsource_MISC"],"url":"https://github.com/NixOS/nix/pull/10178"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/references/1
{"name":"https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4f1ee8ec92182b6ee64cbfb0f6e946544bea4e9a38e632dc238c21b750915df1 · sha256:aac6e3ad237cc649… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.