Description
Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds. This issue was patched in version(s) 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 and 2.18.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37395 | Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds. This issue was patched in version(s) 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 and 2.18.4. |
Ubuntu USN |
USN-7633-1 | Nix vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:12:25.386Z
Reserved: 2024-06-18T16:37:02.729Z
Link: CVE-2024-38531
Updated: 2024-07-08T19:36:56.214Z
Status : Deferred
Published: 2024-06-28T14:15:03.293
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-38531
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:44:55Z
Weaknesses
EUVD
Ubuntu USN