CVE-2024-45593 | Nix affected by unsafe NAR unpacking
Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be with root permissions when using the Nix daemon. This issue is fixed in Nix 2.24.6.
Conclusion & alert: CVE-2024-45593 is rated Moderate Risk (51/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.57%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2024-45593
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
CVE-2024-45593 medium priority: Ubuntu including 1 source packages (nix), 7 status rows across 7 suites (focal, jammy, noble, oracular, plucky, questing, upstream): released 3, not-affected 2, DNE 1, ignored 1.