Vulnerabilities in the package managers Nix, Lix, and Guix.

Vulnerabilities have been identified in the package managers GNU Guix, Nix, and Lix (Nix, Guix, Lix) that allow code execution with the privileges of the users under which the build jobs run (e.g., nixbld* in Nix/Lix). This can be exploited to write one's own data into the build environment and alter the build process. Issues exist within the background processes guix-daemon and nix-daemon, which are used to facilitate access for unprivileged users to build operations.

The vulnerabilities are caused by the use of full file paths instead of dirfd descriptors when performing certain operations for accessing temporary build directories. This allowed for the substitution of the build directory placed within the /tmp hierarchy (e.g., "/tmp/guix-build-PACKAGE-X.Y.drv-0"). Incorrect use of dirfd in the recursive deletion function led to a race condition, allowing the attacker to substitute a symbolic link at the moment between creating and changing the owner of the build directory. Upon successful attack, guix-daemon/nix-daemon would change the owner of the file addressed by the symbolic link instead of switching users for the build directory.

The vulnerabilities have been addressed in updates for Lix 2.93, Nix 2.29, and Guix 1.4.0-38.0e79d5b. To exploit these vulnerabilities, the attacker must have the capability to run arbitrary build jobs. For the attack exploiting vulnerability CVE-2025-46415, it is sufficient to have the ability to create files in the /tmp directory on the build machine. For vulnerability CVE-2025-46416, executing code within the context of the main user ID (pid namespace) and network (network namespace) is required.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster