CVE-2024-45593

NameCVE-2024-45593
DescriptionNix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be with root permissions when using the Nix daemon. This issue is fixed in Nix 2.24.6.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nix (PTS)bullseye2.3.7+dfsg1-1fixed
bookworm2.8.0-1.1fixed
sid, trixie2.24.9+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nixsource(unstable)(not affected)

Notes

- nix <not-affected> (Vulnerable code introduced later)
https://github.com/NixOS/nix/security/advisories/GHSA-h4vv-h3jq-v493
https://github.com/NixOS/nix/commit/eb11c1499876cd4c9c188cbda5b1003b36ce2e59

Search for package or bug name: Reporting problems