VulnerabilityDeferred
CVE-2024-36050
Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
MEDIUM 4.3EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- https://discourse.nixos.org/t/nixpkgs-supply-chain-security-project/34345
- https://discourse.nixos.org/t/security-advisory-privilege-escalations-in-nix-lix-and-guix/66017/26
- https://github.com/NixOS/nix/issues/969
- https://github.com/NixOS/ofborg/issues/68#issuecomment-2082789441
- https://discourse.nixos.org/t/nixpkgs-supply-chain-security-project/34345
- https://github.com/NixOS/nix/issues/969
- https://github.com/NixOS/ofborg/issues/68#issuecomment-2082789441
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.