PT-2024-26864 · Nix+1 · Nix+1

Tomberek

·

Published

2024-05-18

·

Updated

2025-06-27

·

CVE-2024-36050

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nix versions prior to 2.22.1
Description The issue makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request. This is due to the mishandling of certain usage of hash caches.
Recommendations For versions prior to 2.22.1, update to a version that includes the fix for this issue to prevent attackers from replacing source code. As a temporary workaround, consider implementing additional validation and verification steps for pull requests to minimize the risk of accepting malicious changes. Restrict access to hash cache functionality to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2024-36050

Affected Products

Debian
Nix