SB2026040971 - Fedora EPEL 10.3 update for nix
Published: April 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) UNIX Symbolic Link (Symlink) Following (CVE-ID: CVE-2026-39860)
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to unix symbolic link following in fixed-output derivation output registration when copying temporary fixed-output derivation outputs from the build chroot. A remote attacker can create a symlink at the temporary output path to overwrite arbitrary writable files and escalate privileges.
This affects sandboxed Linux builds, while sandboxed macOS builds are unaffected.
Remediation
Install update from vendor's website.