Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44029

Опубликовано: 05 мая 2026
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nixfixed2.34.8+dfsg-1package
nixno-dsatrixiepackage
nixnot-affectedbookwormpackage
nixnot-affectedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/05/04/33

  • https://github.com/NixOS/nix/security/advisories/GHSA-gr92-w2r5-qw5p

  • https://discourse.nixos.org/t/security-advisory-local-privilege-escalation-in-lix-and-nix/77407

EPSS

Процентиль: 43%
0.00573
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

CVSS3: 7.1
redhat
3 месяца назад

An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

CVSS3: 5.3
nvd
3 месяца назад

An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

CVSS3: 5.3
github
3 месяца назад

An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

EPSS

Процентиль: 43%
0.00573
Низкий