CVE-2026-44028Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed. This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-05-05); latest day: 1
  • 10 total mentions across 4 days

Deep dive

Activity timeline10 mentions / 4d
01345Mentions · 2026-05-05: 5Mentions · 2026-05-06: 3Mentions · 2026-05-14: 1Mentions · 2026-06-06: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 3Technical Details · 2026-05-05: 4Technical Details · 2026-05-06: 3Technical Details · 2026-05-14: 1Technical Details · 2026-06-06: 105-0505-0605-1406-06
Signal classification3 categories
Disclosure
440.0%
Patch
440.0%
General
220.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-055
Disclosure3General1Patch1
2026-05-063
Patch3
2026-05-141
General1
2026-06-061
Disclosure1
Full discourse10 posts
  • yousukezan@yousukezan
    Patch

    Nixにおいて、深刻な権限昇格の脆弱性(CVE-2026-44028)が発見された。この問題は、Nixが使用するアーカイブ形式(NAR)のパーサに起因するメモリ破壊バグであり、特にディレクトリ構造を再帰的に処理する際の「無制限再帰」によって発生する。深くネストされた構造を読み込むとスタック領域が枯渇し、オーバーフローが発生する仕組みである。 さらに、この処理はガードページのない小さなコルーチンスタック上で実行されていたため、オーバーフローがヒープ領域にまで影響を及ぼし、メモリ上書きが可能となる。この結果、ASLRを回避できた場合には任意コード実行が可能となり、最終的にはroot権限の奪取につながる危険性がある。特にNixデーモンは通常root権限で動作し、多くのユーザーが接続可能なため影響範囲は広い。 開発側は再帰深度の制限、ガードページ導入、入力検証強化などの対策を実装し、複数の修正版を公開している。利用者には速やかなアップデートが強く推奨される。 https://securityonline.info/nix-daemon-root-privilege-escalation-cve-2026-44028-stack-overflow/

    Post summary

    CVE‑2026‑44028 is a privilege‑escalation flaw in Nix’s NAR parser that can lead to root access; multiple patches are available and users are strongly urged to update promptly.

    0904075.8K
    14.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A 7.5 CVSS flaw in Nix (CVE-2026-44028) allows standard users to gain root privileges via a stack overflow. Update your Nix installation immediately! #Nix #NixOS #CyberSecurity #InfoSec #RootAccess #Linux #Vulnerability #PatchAlert #CVE https://securityonline.info/nix-daemon-root-privilege-escalation-cve-2026-44028-stack-overflow/ https://t.co/v4xtRSIFPl

    Post summary

    The tweet warns of a CVE‑2026‑44028 root privilege escalation flaw in Nix via stack overflow and urges users to update immediately.

    080132890
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    *nix向けパッケージマネージャーNixに権限昇格の脆弱性。CVE-2026-44028はCVSSスコア7.5で、Nixアーカイブ(NAR)パーサにおける無制限再帰によるメモリ破壊。root権限取得可能。修正版提供あり。 https://securityonline.info/nix-daemon-root-privilege-escalation-cve-2026-44028-stack-overflow/

    Post summary

    Nix package manager CVE‑2026‑44028 is a root privilege escalation vulnerability caused by infinite recursion in the NAR parser, rated CVSS 7.5, with a patched version already released.

    02032899
    7.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44028 An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when th… https://www.cve.org/CVERecord?id=CVE-2026-44028

    Post summary

    CVE‑2026‑44028 is a stack‑to‑heap overflow vulnerability in Nix Lix due to unbounded recursion in the NAR parser, affecting versions before 2.34.7 and 2.95.2.

    01010278
    57.4K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    An exploitable integer overflow in Lix (CVE-2026-44028) https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a newly disclosed integer overflow vulnerability (CVE-2026-44028) in Lix, providing a link to a blog post for further details.

    0000036
    1.5K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44028: Nix/Lix Parser Overflow - What It Means for Your Business and How to Respond https://hubs.li/Q04gBzdD0

    Post summary

    The text mentions CVE‑2026‑44028 but lacks substantive detail on exploitation, patches, or active use; it merely alludes to a parser overflow vulnerability.

    0000032
    30 followersView on X
  • SecureChap@SecureChap
    Patch

    A local user with nix-daemon access can feed Lix a crafted NAR file and get root. CVE-2026-44028, disclosed May 5. The bug sits in the NAR parser, introduced during Lix's asyncification rewrite. It reads an 8-byte length field for an archive member name, then allocates a buffer of size 8 + length (rounded to an 8-byte boundary). When length is 2^64 - 8, the addition wraps. Buffer comes back at size zero. Subsequent writes spill into the heap. That gives an out-of-bounds write primitive over the coroutine runtime state. Static builds without PIE get instant root code execution - the daemon runs as root. Dynamic PIE builds need about an hour of brute force to defeat ASLR, millions of attempts. Crafted NARs reach the daemon through substituters, untrusted source paths, or remote builders. Anyone in allowed-users or trusted-users can feed them in. Lix 2.93, 2.94, 2.95 affected. Patched in 2.93.4, 2.94.2, 2.95.2. The fix caps archive member names at 1 MiB. Reported by edef and Sander, with analysis by eldritch horrors. Lix's asyncification logic was inherited from upstream CppNix. The bug almost certainly lives there too. Root daemons that trust their length fields lose them.

    Post summary

    CVE‑2026‑44028 is a heap out‑of‑bounds overflow in Lix’s NAR parser that lets local users gain root, but a patch is already available fixing the overflow by limiting name lengths to 1 MiB.

    0000043
    103 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44028 Stack-to-Heap Overflow in Nix and Lix NAR Parser Leading to Arbit... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44028 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-44028 as a stack‑to‑heap overflow in Nix and Lix NAR parser, but no PoC, exploit, or patch information is included.

    0000044
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-44028 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-44028 #CVE-2026-44028 #CVE #High #CyberSecurity #InfoSec https://t.co/fiDDnYA01A

    Post summary

    The tweet alerts to CVE-2026-44028 with severity 7.5, but provides no details on the vulnerability type, exploitability, or available mitigations.

    0000045
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-44028 An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when th… https://www.cve.org/CVERecord?id=CVE-2026-44028 ----- Traducción: CVE-2026-44028 Se … http://infoflow.cloud`

    Post summary

    The post discusses CVE-2026-44028, noting an unbounded recursion issue in Nix/Lix that could lead to a stack‑to‑heap overflow, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000025
    75 followersView on X

Explore more