PatchSiren

NixOS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW NixOS CVE published 2026-08-20

CVE-2026-64846

A time-of-check/time-of-use race condition in Nix package manager versions prior to 2.35.0 can be exploited by a malicious derivation with the recursive-nix feature. This can potentially allow creation or truncation of empty files outside the build sandbox with the daemon user's permissions. The issue is fixed in version 2.35.0. Defenders should assess exposure and prioritize remediation for Nix deploymen [truncated]