CVE-2026-64846
Last modified
CVE-2026-64846 is a low-severity vulnerability rated 2.8/10 on the CVSS scale. Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user's permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| NixOS | nix | < 2.35.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64846?
How severe is CVE-2026-64846?
How do I fix CVE-2026-64846?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6484In an UEFI, Lack of verified boot to certain FV may cause ar…8.2
- CVE-2026-64840Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-64841Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-64842Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-64843Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-64844Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-64847AnyIO is a high level asynchronous concurrency and networkin…6.8
- CVE-2026-64849MLflow is an open source AI engineering platform for agents,…9.3
- CVE-2026-6485UEFI BIOS embedded Shell could be used to bypass Secure Boot…8.2
- CVE-2026-64850Grav is a file-based Web platform. Prior to 2.0.7, Grav Blue…8.7
- CVE-2026-64851Grav Shortcode Core Plugin allows for the development shortc…8.5
- CVE-2026-64852Grav API Plugin is a RESTful API for Grav CMS that provides …8.7
Are you affected by CVE-2026-64846?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
