PT-2024-28057 · Nix+3 · Nix+3

Alois31

+1

·

Published

2024-06-28

·

Updated

2025-07-14

·

CVE-2024-38531

CVSS v3.1

3.6

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nix versions prior to 2.23.1 Nix versions prior to 2.22.2 Nix versions prior to 2.21.3 Nix versions prior to 2.20.7 Nix versions prior to 2.19.5 Nix versions prior to 2.18.4
Description Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds.
Recommendations For versions prior to 2.23.1, update to version 2.23.1 or later. For versions prior to 2.22.2, update to version 2.22.2 or later. For versions prior to 2.21.3, update to version 2.21.3 or later. For versions prior to 2.20.7, update to version 2.20.7 or later. For versions prior to 2.19.5, update to version 2.19.5 or later. For versions prior to 2.18.4, update to version 2.18.4 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-38531
GHSA-Q82P-44MG-MGH5
USN-7633-1

Affected Products

Debian
Linuxmint
Nix
Ubuntu