PT-2024-26864 · Nix+1 · Nix+1
Tomberek
·
Published
2024-05-18
·
Updated
2025-06-27
·
CVE-2024-36050
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nix versions prior to 2.22.1
Description
The issue makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request. This is due to the mishandling of certain usage of hash caches.
Recommendations
For versions prior to 2.22.1, update to a version that includes the fix for this issue to prevent attackers from replacing source code. As a temporary workaround, consider implementing additional validation and verification steps for pull requests to minimize the risk of accepting malicious changes. Restrict access to hash cache functionality to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Nix