Protection Mechanism Failure Affecting nixos/nix package, versions [,2.18.9) [2.19.0,2.19.7) [2.20.0,2.20.9) [2.21.0,2.21.5) [2.22.0,2.22.4) [2.23.0,2.23.4) [2.24.0,2.24.10)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team

    Threat Intelligence

    EPSS
    0.04% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-UNMANAGED-NIXOSNIX-8322157
  • published 1 Nov 2024
  • disclosed 31 Oct 2024
  • credit Unknown

How to fix?

Upgrade nixos/nix to version 2.18.9, 2.19.7, 2.20.9, 2.21.5, 2.22.4, 2.23.4, 2.24.10 or higher.

Overview

Affected versions of this package are vulnerable to Protection Mechanism Failure due to improper execution of built-in builders outside the macOS sandbox environment. An attacker can gain unauthorized read and write access to system paths by exploiting this misconfiguration.

Note: This is only exploitable if sandboxing is not enabled, which is the default setting on macOS.

References

CVSS Scores

version 4.0
version 3.1
Expand this section

Snyk

Recommended
1 low
  • Attack Vector (AV)
    Local
  • Attack Complexity (AC)
    High
  • Attack Requirements (AT)
    Present
  • Privileges Required (PR)
    Low
  • User Interaction (UI)
    Passive
  • Confidentiality (VC)
    Low
  • Integrity (VI)
    Low
  • Availability (VA)
    None
  • Confidentiality (SC)
    Low
  • Integrity (SI)
    Low
  • Availability (SA)
    None