CVE-2024-36050: Medium severity Nix Nix vulnerability
Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36050?
The severity of CVE-2024-36050 is considered critical due to the potential for attackers to replace source code through social engineering.
How do I fix CVE-2024-36050?
To fix CVE-2024-36050, upgrade to Nix version 2.22.2 or later, which addresses the hash cache handling issue.
What software versions are affected by CVE-2024-36050?
CVE-2024-36050 affects Nix versions up to and including 2.22.1.
What type of attack does CVE-2024-36050 enable?
CVE-2024-36050 enables supply chain attacks by allowing attackers to replace legitimate source code with malicious code.
Who is primarily impacted by CVE-2024-36050?
Developers and maintainers using vulnerable versions of Nix could be lured into accepting malicious pull requests due to CVE-2024-36050.