漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Nix: Arbitrary file truncation outside the sandbox with recursive-nix experimental feature
Vulnerability Description
Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user's permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
CWE-61
Vulnerability Title
Nix 竞争条件问题漏洞
Vulnerability Description
Nix是Nix组织开源的一个可复现构建与包管理的系统工具。 Nix 2.35.0之前版本存在安全漏洞,该漏洞源于LocalStore恢复路径中最终符号链接处理的检查时间/使用时间竞争条件,可能导致Nix进程或nix-daemon在构建沙箱外以守护进程用户权限创建或截断空文件。
CVSS Information
N/A
Vulnerability Type
N/A