https://seclists.org/oss-sec/2026/q2/401: Nix/Lix: local privilege escalation in daemon process
Published May 4, 2026
·Updated
Affected Software
2 affected components
Nix
Lix
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
CVE-2026-XXXX has been classified as a high severity local privilege escalation vulnerability.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, users should upgrade to the latest version of Nix or Lix as provided in the security advisory.
3
What versions are affected by CVE-2026-XXXX?
The specific affected versions of Nix and Lix can be found in the security advisory published on discourse.nixos.org.
4
Who is impacted by CVE-2026-XXXX?
Any user running vulnerable versions of Nix or Lix daemon processes is at risk due to CVE-2026-XXXX.
5
Are there any mitigations for CVE-2026-XXXX?
While fixes are available, users should refer to the security advisory for any additional mitigations related to CVE-2026-XXXX.