Skip to content

GHSA-6h4g-g5j9-fm5f on CTRL-OS 26.05

Aliases: GHSA-6h4g-g5j9-fm5f

Packages: nix

Status: Plausible

Advisory Information

Impact

With the recursive-nix experimental feature enabled, a malicious derivation can exploit a TOCTOU race to get the nix process to truncate or create an empty file outside of the build sandbox as the user running the nix process (or nix-daemon).

Fix

The issue is fixed in Nix 2.35.0. Prior versions will not be receiving the fixes due to the limited impact, a prerequisite of enabling the recursive-nix experimental feature and the complexity of the fix.

Updates

2026-07-14 17:22 CEST

Metadata changes:

  • Status for package nix: “Plausible

Comment:

With the recursive-nix experimental feature enabled

2026-07-14 16:02 CEST

Metadata changes:

  • Status for package nix: “New