Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 42 Nix Critical Privilege Escalation Fix GHSA-g3g9-5vj6-r3gj

fedora
Calendar Grey April 17, 2026
Dist Fedora Esm H88
Critical update fixes privileged access issue in Nix on Fedora 42, addressing significant security threats efficiently.
update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj

Summary

Nix is a purely functional package manager.

It allows multiple versions of a package to be installed side-by-side,

ensures that dependency specifications are complete,

supports atomic upgrades and rollbacks,

allows non-root users to install software, and has many other features.

It is the basis of the NixOS Linux distribution,

but it can be used equally well under other Unix systems.

See the README.fedora.md file for setup instructions.

Update Information:

update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj

Change Log

* Wed Apr 8 2026 Jens Petersen - 2.31.4-1 - update to 2.31.4 - fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) * Wed Apr 8 2026 Jens Petersen - 2.31.3-2 - sync readme/gating/tests improvements from rawhide/f44 - document nixGL - enable gating on tier0 and install CI tests

References


[ 1 ] Bug #2456893 - CVE-2026-39860 nix: privilege escalation via symlink following during output registration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456893

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-02fa328deb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: nix
Product: Fedora 42
Version: 2.31.4
Release: 1.fc42
Summary: A purely functional package manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here