๐Ÿ” CVE Alert

CVE-2026-64846

LOW 2.8

Nix: Arbitrary file truncation outside the sandbox with recursive-nix experimental feature

CVSS Score
2.8
EPSS Score
0.0%
EPSS Percentile
0th

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user's permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0.

CWE CWE-61 CWE-367
Vendor nixos
Product nix
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for nixos nix

Be the first to know when new low vulnerabilities affecting nixos nix are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

NixOS / nix
< 2.35.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f github.com: https://github.com/NixOS/nix/pull/15401 github.com: https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390