logo

Nix Vulnerability Grants Root Access via NAR Parser Overflow

ID: c41d5efa-6732-5a2a-bc56-28c44f5a27cf

STIX ID: report--c41d5efa-6732-5a2a-bc56-28c44f5a27cf

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Ddos

...
...

CVE-2026-44028 is a high-priority stack overflow vulnerability in the Nix Archive (NAR) parser allowing a local user with access to the Nix daemon to potentially gain root via unbounded recursion on coroutine stacks; maintainers released fixes including a 64-level recursion limit, guard pages for coroutine stacks, symlink and filename sanitization, and limits on worker crash forks—users running Nix since 2.24.4 should upgrade to the patched releases immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.