ThreatCluster[verified]@threatclusterPatch
CVE‑2026‑39860 is a critical privilege‑escalation flaw in Nix, fixed in Fedora 42/43; users should update to Nix 2.31.4 via dnf.
Gray Hats@the_yellow_fallPatch
The tweet announces that NixOS has patched CVE-2026-39860, a critical sandbox escape that enables root takeover via symlink manipulation, urging users to update. No exploit code or active exploitation is mentioned.
Tom Sydney Kerckhove@kerckhove_tsPatch
NixCI installations were updated to patch CVE-2026-39860, after wiping affected workers; no PoC, exploit, or technical detail is given.
CCB Alert@CCBalertDisclosure
A critical CVE-2026-39860 vulnerability in NixOS allows authenticated users to overwrite arbitrary files by following symlinks in the Nix daemon; patch details are available via the linked NixOS advisory.
CVEFind.com@CveFindComPatch
The post announces that CVE-2026-39860, a critical root‑privilege escalation bug in Nix, has been fixed in version 2.34.5 and notes the vulnerability allows arbitrary overwrites.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-39860, highlighting a flaw that permits arbitrary file overwrites by the Nix process, without providing a PoC, exploit, or patch information.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑39860, describing how a flaw in the Nix package manager’s fix for a prior CVE permits arbitrary file overwrites on systems where the Nix process can write, but no PoC, exploit, patch, or active exploitation details are provided.
0day Signal@0dayPublishingDisclosure
The text announces CVE-2026-39860, describing a symlink race in the Nix sandbox that allows trivial root escalation; no patch, PoC, or exploitation claim is provided.