{"apiVersion":"1.0","identifier":"CVE-2026-64846","description":"Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user-s permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0.","publishedAt":"2026-08-20T17:19:16","lastModifiedAt":"2026-08-20T20:17:45","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64846","cvssScore":2.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","epssProbability":0.00088,"riskScore":0.28,"affectedProduct":"Nix","affectedVersions":"<2.35.0","vulnerabilityType":"Critical software","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-64846","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-64846","en":"https://www.redsauce.net/en/cves/CVE-2026-64846","fr":"https://www.redsauce.net/fr/cves/CVE-2026-64846","pt":"https://www.redsauce.net/pt/cves/CVE-2026-64846","de":"https://www.redsauce.net/de/cves/CVE-2026-64846","sk":"https://www.redsauce.net/sk/cves/CVE-2026-64846","el":"https://www.redsauce.net/el/cves/CVE-2026-64846"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-64846"}}