SB2026040968 - Fedora 44 update for nix



SB2026040968 - Fedora 44 update for nix

Published: April 9, 2026

Security Bulletin ID SB2026040968
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) UNIX Symbolic Link (Symlink) Following (CVE-ID: CVE-2026-39860)

CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to unix symbolic link following in fixed-output derivation output registration when copying temporary fixed-output derivation outputs from the build chroot. A remote attacker can create a symlink at the temporary output path to overwrite arbitrary writable files and escalate privileges.

This affects sandboxed Linux builds, while sandboxed macOS builds are unaffected.


Remediation

Install update from vendor's website.