CVE-2025-46416

Source
https://cve.org/CVERecord?id=CVE-2025-46416
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46416.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-46416
Downstream
Published
2025-06-27T14:15:38Z
Modified
2025-09-06T18:00:20Z
Summary
[none]
Details

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

References

Affected packages