Nix 2.24 is vulnerable to (remote) privilege escalation

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

CodeRabbit: AI Code Reviews for Developers
Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.
coderabbit.ai
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  1. matrix.to

    A simple stateless privacy-protecting URL redirecting service for Matrix

    This message was sent last Sunday in a public Matrix discussion involving the author.

    > Eelco is working on it, there's a patch on the GitHub advisory, we plan to get it out on Monday, but no promises yet if everything will get done by then

    https://matrix.to/#/!VRULIdgoKmKPzJZzjj:nixos.org/$tJgEBGqKs...

    In what world is this "not being in touch," "actively ignoring messages," "not forwarding the researcher to anyone else"? Also, Nix maintainers clearly state that they weren't "aware" of the deadline. Very different definitions of words indeed.

  2. CodeRabbit

    CodeRabbit: AI Code Reviews for Developers. Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.

    CodeRabbit logo
  3. nix

    Nix, the purely functional package manager

    This is fixed in 2.24.6: https://github.com/NixOS/nix/releases/tag/2.24.6

    See also https://discourse.nixos.org/t/vulnerability-in-nix-2-24/5190... for updates.

    Can someone link to the actual fix? It's a bit hard to navigate the git history for me...

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • How many Alpine packages can you install at once?

    2 projects | news.ycombinator.com | 21 Jan 2025
  • Customize Go Builds on AWS SAM with Dockerfiles and Makefiles

    2 projects | dev.to | 19 Jan 2025
  • How to start using nix?

    1 project | dev.to | 8 Nov 2024
  • Developing with Docker

    2 projects | news.ycombinator.com | 24 Oct 2024
  • ❄️ NixOS: OS as Code

    2 projects | dev.to | 13 Oct 2024

Did you know that C++ is
the 7th most popular programming language
based on number of references?