CVE-2026-39860Disclosure(linux / linux_kernel)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the build chroot. A symlink, pointing to an arbitrary location in the filesystem, could be created by the derivation builder at that path. During output registration, the Nix process (running in the host mount namespace) would follow that symlink and overwrite the destination with the derivation's output contents. In multi-user installations, this allows all users able to submit builds to the Nix daemon (allowed-users - defaulting to all users) to gain root privileges by modifying sensitive files. This vulnerability is fixed in 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, and 2.28.6.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • nix

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 4 mentions (2026-04-08); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
linux_kernelnix

1 version affected across 2 products

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-04-08: 4Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-09: 2Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-17: 104-0804-0904-1004-17
Signal classification2 categories
Disclosure
450.0%
Patch
450.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-084
Disclosure3Patch1
2026-04-092
Disclosure1Patch1
2026-04-101
Patch1
2026-04-171
Patch1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Patch

    Nix patches a critical 9.0 CVSS sandbox escape. Learn how CVE-2026-39860 allows unprivileged users to seize root control via symlink manipulation. Update now! #NixVulnerability #CyberSecurity #LinuxSecurity #RootEscalation #InfoSec #NixOS https://securityonline.info/nix-package-manager-sandbox-escape-cve-2026-39860/ https://t.co/vkqIp1sR5r

    Post summary

    The tweet announces that NixOS has patched CVE-2026-39860, a critical sandbox escape that enables root takeover via symlink manipulation, urging users to update. No exploit code or active exploitation is mentioned.

    15082717
    12.3K followersView on X
  • Tom Sydney Kerckhove@kerckhove_ts
    Patch

    All NixCI installations have upgraded to mitigate CVE-2026-39860 and all workers have been wiped. Thanks to everyone who was involved in finding and fixing this!

    Post summary

    NixCI installations were updated to patch CVE-2026-39860, after wiping affected workers; no PoC, exploit, or technical detail is given.

    101701.4K
    4.0K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerability in #NixOS. CVE-2026-39860 CVSS: 9.0. Authenticated users can abuse the Nix daemon to overwrite arbitrary file. The daemon will follow symlinks when writing output during the build process. More info: https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj #Patch #Patch #Patch

    Post summary

    A critical CVE-2026-39860 vulnerability in NixOS allows authenticated users to overwrite arbitrary files by following symlinks in the Nix daemon; patch details are available via the linked NixOS advisory.

    01000252
    7.2K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical Nix privilege escalation CVE-2026-39860 fixed in Fedora 42 and 43, users urged to upgrade to Nix 2.31.4 via dnf to block non-root privilege escalation. https://threatcluster.io/cluster/critical-privilege-escalation-flaw-in-nix-package-manager-fi-eb0cccf6

    Post summary

    CVE‑2026‑39860 is a critical privilege‑escalation flaw in Nix, fixed in Fedora 42/43; users should update to Nix 2.31.4 via dnf.

    0000062
    155 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39860: CRITICAL] Critical security vulnerability fixed in Nix 2.34.5, impacting Linux builds. Exploiting a bug allowed arbitrary overwrites enabling users to gain root privileges.#cve,CVE-2026-39860,#cybersecurity https://cvefind.com/CVE-2026-39860

    Post summary

    The post announces that CVE-2026-39860, a critical root‑privilege escalation bug in Nix, has been fixed in version 2.34.5 and notes the vulnerability allows arbitrary overwrites.

    0000043
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39860 Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process o… https://www.cve.org/CVERecord?id=CVE-2026-39860 ----- Traducción: CVE-2026-39860 Nix… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-39860, highlighting a flaw that permits arbitrary file overwrites by the Nix process, without providing a PoC, exploit, or patch information.

    0000072
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39860 Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process o… https://www.cve.org/CVERecord?id=CVE-2026-39860

    Post summary

    The text announces CVE‑2026‑39860, describing how a flaw in the Nix package manager’s fix for a prior CVE permits arbitrary file overwrites on systems where the Nix process can write, but no PoC, exploit, patch, or active exploitation details are provided.

    00000188
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39860: Nix sandbox escape: file write v... Broken sandbox fix creates trivial root escalation via symlink race - any user can pwn the Nix daemon through FOD outpu... https://zerodaysignal.com/vulnerability/CVE-2026-39860 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE-2026-39860, describing a symlink race in the Nix sandbox that allows trivial root escalation; no patch, PoC, or exploitation claim is provided.

    0000067
    204 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
Appnixosnix---

Explore more