Security Advisory: Privilege Escalations in Nix, Lix and Guix
Summary This advisory follows up on the pre-announcement made last week. Nix and Lix are affected by a set of issues that can be combined to achieve root privilege escalation. These issues are identified as: CVE-2025-46415 CVE-2025-52991 CVE-2025-52992 CVE-2025-52993 Additionally, a privilege escalation to the build users (nixbld*) has been identified. This issue is known as CVE-2025-46416. This issue is only mitigated by Lix when the Pasta or LSM mitigations are enabled. This is a coordina...
discourse.nixos.org Β· NixOS Discourse