216.73.216.6

CVE-2025-46416

· Published 27/06/2025 14:15 · Modified 27/06/2025 14:15

Labels: CVE-2025-46416 2025-06-27CVE-2025-46416CWE-282[email protected]

Essential information

Published
27/06/2025 14:15
Modified
27/06/2025 14:15
Author
Creator
CVSS
2.9 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS metrics

Description

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nix / nix cpe:2.3:a:nix:nix:<2.24.15-2.29.1:*:*:*:*:*:*:*
lix / lix cpe:2.3:a:lix:lix:<2.91.2-2.93.1:*:*:*:*:*:*:*
guix / guix cpe:2.3:a:guix:guix:<1.4.0:*:*:*:*:*:*:*

References