#1135777 nix: CVE-2026-44028 CVE-2026-44029

Package:
src:nix
Source:
src:nix
Submitter:
Salvatore Bonaccorso
Date:
2026-07-13 01:21:03 UTC
Severity:
normal
Tags:
#1135777#5
Date:
2026-05-05 20:15:53 UTC
From:
To:
Hi,

The following vulnerabilities were published for nix.

CVE-2026-44028[0]:
| An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2.
| Unbounded recursion in the NAR (Nix Archive) parser could lead to a
| stack-to-heap overflow when the parser is run on a coroutine stack.
| The stack is allocated without a guard page, which means that a
| stack overflow could overwrite memory on the heap and could allow
| arbitrary code execution as the Nix daemon (run as root in multi-
| user installations) if ASLR hardening is bypassed. This can be
| exploited by all users able to connect to the daemon (e.g., in Nix,
| this is configurable via the allowed-users setting, defaulting to
| all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5,
| 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and
| 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0).


CVE-2026-44029[1]:
| An issue was discovered in Nix before 2.34.7. Writing to arbitrary
| files can occur via "nix-prefetch-url --unpack" or "nix store
| prefetch-file --unpack" directory traversal. The fixed versions are
| 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7
| (introduced in 2.24.7);


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-44028
https://www.cve.org/CVERecord?id=CVE-2026-44028
[1] https://security-tracker.debian.org/tracker/CVE-2026-44029
https://www.cve.org/CVERecord?id=CVE-2026-44029

Regards,
Salvatore

#1135777#10
Date:
2026-07-13 01:19:43 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nix, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1135777@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jordan Justen <jljusten@debian.org> (supplier of updated nix package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 12 Jul 2026 16:41:36 -0700
Source: nix
Architecture: source
Version: 2.34.8+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Jordan Justen <jljusten@debian.org>
Changed-By: Jordan Justen <jljusten@debian.org>
Closes: 1122795 1135777
Changes:
 nix (2.34.8+dfsg-1) unstable; urgency=medium
 .
   [ Jordan Justen ]
   * New upstream release (Closes: #1135777),
     Fixes CVE-2026-44028 and CVE-2026-44029.
 .
   [ Michael Biebl ]
   * d/control: Drop Build-Depends on dh-sequence-movetousr (Closes: #1122795)
Checksums-Sha1:
 785a80a014348c835b3718d1759594386fc172c5 2920 nix_2.34.8+dfsg-1.dsc
 4a4bd7f68915d777e1b86702452fa8fbaf84f016 1545040 nix_2.34.8+dfsg.orig.tar.xz
 ce51b885cf530f9144ea6eb73a3cd7949349d2b9 14400 nix_2.34.8+dfsg-1.debian.tar.xz
 85dc38079929d0ba30cafcd9fb723a9cd4652051 12125 nix_2.34.8+dfsg-1_source.buildinfo
Checksums-Sha256:
 a8ed55eb104460f289befa3c79c060397bdaaf7c68661a9f9475840aaa8a814a 2920 nix_2.34.8+dfsg-1.dsc
 2042e5b5e83d323b37b0e5c0b479316ba74ea507a91eed7729a239bbff1ca1eb 1545040 nix_2.34.8+dfsg.orig.tar.xz
 b704d551646cfeecada5a5daaa20f0711d3715b838cab960d212e7317423210c 14400 nix_2.34.8+dfsg-1.debian.tar.xz
 d884453f860fd4babd41c329f16491fe59bd6d744ff41de144a0536305cb0eea 12125 nix_2.34.8+dfsg-1_source.buildinfo
Files:
 b21901129029a2fbc3cd49778ad960da 2920 devel optional nix_2.34.8+dfsg-1.dsc
 eb77975e5b629ff83a70f28d1519c103 1545040 devel optional nix_2.34.8+dfsg.orig.tar.xz
 a9029ddfc1a753e6170d718f728a3372 14400 devel optional nix_2.34.8+dfsg-1.debian.tar.xz
 9c4e1c332d9aebd7c5ac0c12f43ab7d5 12125 devel optional nix_2.34.8+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEwnSFIXQUyd8CMWwuN/mfaMr5kusFAmpUJqwACgkQN/mfaMr5
kuu+ERAAkQuOoSkIWlb2FKY18oPhQPQqFURQSvQOPoHhFmB6jfs/BgInkyoy0Iky
tmhfZCER4i5aX0lbYukBbHW+50KYa2SAIZtUBgTuP6WfzIg/HNGXtd98kbChWCVJ
hfP+3i+GSkK55QeXvQaIauBsDEjd4hK64nBll2lgMNSZtjgg4sWvZYbJzvYj5Y6Q
XsH8cWBuWIm0IdVKvK22/grnx0ox8EmqbLVqke7AFsh2aV7Na31ckApoc914+ZEv
GykJPC0O2eDVBvQAYuTPeWp0JB14uuTnNUPuce6gS+6gwYH3IKwdUpBRu73sFKSP
6Fn1ZsMlNfQqRZYcVEQQdQKux9vJft8YQxa7Lh3IDCiCANM08Dv9wSrgITFoQlVN
37uLnkzRghAEtgrqI62s3Qv1xiRpHig4X+BdQW/ao9McHKlfqKrYCSTYYwqo0K/A
7YOgp2FWmWG5yGOrdHnkbe81RahGm9R+csHO1vhDl7X2UxGK74EgsesfYQ3H1UUX
rfF2+0WBgI+jrGfQCP9sim6vh04JVxWs/LbwN1cq035OWTQ97bpKV261hNLxexke
U9wqb8FThAZQG3Lcz8KyEqmYIGJrUMNM3mHuLTs2/83fZegs22Ijg3S6kE0ZtU5x
R0V7Ai5sQtfmNc173oIR+BhyO7UUEpt5CgTCUugK7efjBxbKk/I=
=90+O
-----END PGP SIGNATURE-----