CVE-2026-39860
NixOS nix, linux kernel
Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the build chroot. A symlink, pointing to an arbitrary location in the filesystem, could be created by th...
- CVSS
- 8.4
- EPSS
- 0.19% 9.23% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.09