UNIX Symbolic Link (Symlink) Following in nix - CVE-2026-39860

 

UNIX Symbolic Link (Symlink) Following in nix - CVE-2026-39860

Published: April 8, 2026 / Updated: April 9, 2026


Vulnerability identifier: #VU125379
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-39860
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to unix symbolic link following in fixed-output derivation output registration when copying temporary fixed-output derivation outputs from the build chroot. A remote attacker can create a symlink at the temporary output path to overwrite arbitrary writable files and escalate privileges.

This affects sandboxed Linux builds, while sandboxed macOS builds are unaffected.


Affected software

nix
Fedora
nix

How to mitigate CVE-2026-39860

Install security update from vendor's website.

nix - addressed in versions 2.28.6, 2.29.3, 2.30.4, 2.31.4, 2.32.7, 2.33.4, 2.34.5
nix - addressed in versions 2.24.15-2.el10_1, 2.24.15-2.el10_2, 2.24.15-2.el10_3, 2.31.4-1.fc42, 2.31.4-1.fc43, 2.34.5-1.fc44

External References

Related Security Bulletins