UNIX Symbolic Link (Symlink) Following in nix - CVE-2026-39860
Published: April 8, 2026 / Updated: April 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to unix symbolic link following in fixed-output derivation output registration when copying temporary fixed-output derivation outputs from the build chroot. A remote attacker can create a symlink at the temporary output path to overwrite arbitrary writable files and escalate privileges.
This affects sandboxed Linux builds, while sandboxed macOS builds are unaffected.
Affected software
Fedora
nix
How to mitigate CVE-2026-39860
nix - addressed in versions 2.24.15-2.el10_1, 2.24.15-2.el10_2, 2.24.15-2.el10_3, 2.31.4-1.fc42, 2.31.4-1.fc43, 2.34.5-1.fc44