discourse.nixos.org
https://discourse.nixos.org/t/security-advisory-privilege-escalations-in-nix-lix-and-guix/66017 CVE-2025-46416
LOW
Record summary
CVE-2025-46416 has a selected CVSS score of 2.9 (low).
Description
The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | Through 2.24.15 | affected |
| 2.25.0 to ≤ 2.26.4 | affected | ||
| 2.27.0 to ≤ 2.28.4 | affected | ||
| 2.29.0 to ≤ 2.29.1 | affected |
References
7guix.gnu.org
https://guix.gnu.org/en/blog/2025/privilege-escalation-vulnerabilities-2025 labs.snyk.io
https://labs.snyk.io/ lix.systems
https://lix.systems/blog/2025-06-24-lix-cves nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-46416 security-tracker.debian.org
https://security-tracker.debian.org/tracker/CVE-2025-46416 security.snyk.io
https://security.snyk.io/vuln?search=CVE-2025-46416