CVE-2024-38531

Publication date 28 June 2024

Last updated 14 July 2025


Ubuntu priority

Cvss 3 Severity Score

3.6 · Low

Score breakdown

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds. This issue was patched in version(s) 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 and 2.18.4.

Status

Package Ubuntu Release Status
nix 25.04 plucky
Not affected
24.10 oracular Ignored end of life, was needed
24.04 LTS noble
Fixed 2.18.1+dfsg-1ubuntu5+esm2
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Fixed 2.6.0+dfsg-3ubuntu0.1~esm1
20.04 LTS focal Not in release

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro 30-day free trial

Severity score breakdown

Parameter Value
Base score 3.6 · Low
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L