CVE-2024-38531

Publication date 28 June 2024

Last updated 25 June 2025


Ubuntu priority

Cvss 3 Severity Score

3.6 · Low

Score breakdown

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds. This issue was patched in version(s) 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 and 2.18.4.

Status

Package Ubuntu Release Status
nix 25.04 plucky
Not affected
24.10 oracular
Vulnerable
24.04 LTS noble
Vulnerable
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Vulnerable
20.04 LTS focal Not in release

Severity score breakdown

Parameter Value
Base score 3.6 · Low
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L