PT-2024-9884 · Nix+2 · Nix+2

Puckipedia

·

Published

2024-09-10

·

Updated

2025-11-21

·

CVE-2024-45593

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Nix versions 2.24 through 2.24.5 Nix version 2.24 prior to 2.24.6
Description: A bug in Nix allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be with root permissions when using the Nix daemon. The issue is related to improper restriction of the directory path name with limited access. Exploitation of the issue may allow a remote attacker to overwrite arbitrary files in the system.
Recommendations: For Nix versions 2.24 through 2.24.5, update to Nix 2.24.6 to patch the bug. For Nix version 2.24 prior to 2.24.6, update to Nix 2.24.6 to fix the issue. As a temporary workaround, consider restricting access to the Nix daemon to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-11662
CVE-2024-45593
GHSA-H4VV-H3JQ-V493
USN-7633-1

Affected Products

Linuxmint
Nix
Ubuntu