CVE-2025-52993: Race Condition
A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld or guixbuild). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52993?
CVE-2025-52993 is rated as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-52993?
To fix CVE-2025-52993, upgrade Nix to versions 2.24.15, 2.26.4, 2.28.4, or 2.29.1; Lix to versions 2.91.2, 2.92.2, or 2.93.1; and Guix to version 1.4.0 or later.
What systems are affected by CVE-2025-52993?
CVE-2025-52993 affects Nix, Lix, and Guix package managers prior to their respective fixed versions.
Can CVE-2025-52993 lead to file ownership changes?
Yes, CVE-2025-52993 can allow an attacker to change the ownership of arbitrary files to the UID and GID of the build user.
What are the implications of CVE-2025-52993?
The implications of CVE-2025-52993 include the risk of unauthorized access and manipulation of file permissions, leading to potential security breaches.