logo

Root Access at Risk: Critical Nix Sandbox Escape Overwrites Sensitive System Files

ID: 063865b1-87b3-55aa-a39c-403c14af6830

STIX ID: report--063865b1-87b3-55aa-a39c-403c14af6830

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical sandbox-escape vulnerability (CVE-2026-39860, CVSS 9.0) in the Nix package manager enables unprivileged users on multi-user Linux installations to create a malicious symlink during fixed-output derivation output registration, causing the root-run Nix daemon to follow the link and overwrite sensitive host files (e.g., /etc/shadow), allowing local privilege escalation to root; fixes for multiple 2.28–2.34 branches have been released and administrators should apply patches or restrict who can submit builds and access the daemon socket.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.