CVE-2024-45593
Nix affected by unsafe NAR unpacking
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be with root permissions when using the Nix daemon. This issue is fixed in Nix 2.24.6.
Linus Heckemann discovered that Nix did not correctly handle certain binaries. An attacker could possibly use this issue to execute arbitrary code. Pierre-Etienne Meunier discovered that Nix did not correctly handle TLS certificates. A remote attacker could possibly use this issue to leak sensitive information. It was discovered that Nix did not correctly handle Unix sockets. An attacker could possibly use this issue execute arbitrary code. This issue only affected Ubuntu 24.04 LTS.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-09-02 CVE Reserved
- 2024-09-10 CVE Published
- 2024-09-10 CVE Updated
- 2025-07-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/NixOS/nix/commit/eb11c1499876cd4c9c188cbda5b1003b36ce2e59 | X_refsource_misc | |
https://github.com/NixOS/nix/security/advisories/GHSA-h4vv-h3jq-v493 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
NixOS Search vendor "NixOS" | Nix Search vendor "NixOS" for product "Nix" | >= 2.24.0 < 2.24.6 Search vendor "NixOS" for product "Nix" and version " >= 2.24.0 < 2.24.6" | en |
Affected
|