Bug 2456813 (CVE-2026-39860)
| Summary: | CVE-2026-39860 nix: privilege escalation via symlink following during output registration | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | MODIFIED --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Nix. This vulnerability allows local users, who can submit builds to the Nix daemon, to create a symbolic link (symlink) during the output registration process of fixed-output derivations. The Nix process, running with elevated privileges, would then follow this symlink, leading to an arbitrary file overwrite. This could enable an attacker to modify sensitive system files and gain root privileges.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2456892, 2456893 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-08 22:05:38 UTC
|