CVE-2024-38531

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds. This issue was patched in version(s) 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 and 2.18.4.

Scoring

Severity
LOW
CVSS base score
3.6
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS probability
0.14%
CWE
CWE-278
Published
2024-06-28
Last modified
2026-03-13

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs