<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – NixOS</title>
  <link>https://cvedaily.com/pages/tags/nixos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nixos.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – NixOS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-44592 – Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44592</guid>
    <pubDate>Thu, 14 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44592</strong></p>
  <p>Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker without any credentials by sending a fresh, never-registered worker UUID. The resulting session has PeerAuth::Open, i.e. it sees jobs from every organisation, and can immediately NarPush/NarUploaded arbit…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-71229 – In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw88...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-71229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-71229</guid>
    <pubDate>Wed, 18 Feb 2026 16:22:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-71229</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()  rtw_core_enable_beacon() reads 4 bytes from an address that is not a multiple of 4. This results in a crash on some systems.  Do 1 byte reads/writes instead.  Unable to handle kernel paging request at virtual address ffff8000827e0522 Mem abort info:   ESR = 0x00000000…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-71229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25137 – The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25137</guid>
    <pubDate>Mon, 02 Feb 2026 23:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25137</strong></p>
  <p>The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Unauthorized access is evident from http requests. If kept, searching access logs and/or Odoos log fo…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23838 – Tandoor Recipes is a recipe manager than can be installed with the Nix package m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23838</guid>
    <pubDate>Mon, 19 Jan 2026 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23838</strong></p>
  <p>Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `MEDIA_ROOT`, the full database file may be externally accessible, potentially on the Internet. The root cause is that the NixOS module configures the working dir…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64766 – NixOS's Onlyoffice is a software suite that offers online and offline tools for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64766</guid>
    <pubDate>Mon, 17 Nov 2025 22:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64766</strong></p>
  <p>NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 and versions before Unstable 25.11, a hard-coded secret was used in the NixOS module for the OnlyOffice document server to protect its file cache. An attacker with knowledge of an existing revision ID could use this secret to obtai…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32438 – make-initrd-ng is a tool for copying binaries and their dependencies. Local priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32438</guid>
    <pubDate>Tue, 15 Apr 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32438</strong></p>
  <p>make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default) a local user is able to create a program that will be executed by root during shutdown. Patches exist for NixOS 24.11 and 25.05 / unstable. As a workaround, set systemd.shutdownRamfs.enable = false;.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-378</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49335 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49335</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49335</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/cs: make commands with 0 chunks illegal behaviour.  Submitting a cs with 0 chunks, causes an oops later, found trying to execute the wrong userspace driver.  MESA_LOADER_DRIVER_OVERRIDE=v3d glxinfo  [172536.665184] BUG: kernel NULL pointer dereference, address: 00000000000001d8 [172536.665188] #PF: supervisor read acc…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45049 – Hydra is a Continuous Integration service for Nix based projects. It is possible...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45049</guid>
    <pubDate>Tue, 27 Aug 2024 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45049</strong></p>
  <p>Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size of evaluations, this can impact the availability of systems. The problem can be fixed by applying https://github.com/NixOS/hydra/commit/f73043378907c2c7e44f633ad764c8bdd1c947d5 to any Hydra package. Users are advised to upgrade. Users u…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43378 – calamares-nixos-extensions provides Calamares branding and modules for NixOS, a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43378</guid>
    <pubDate>Fri, 16 Aug 2024 02:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43378</strong></p>
  <p>calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning to create a setup where the system was booted via legacy BIOS rather than UEFI; some disk partitions are encrypted; but the partitions containing either `/` or `/boot` are unencrypted; have their LUKS…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32657 – Hydra is a Continuous Integration service for Nix based projects. Attackers can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32657</guid>
    <pubDate>Mon, 22 Apr 2024 23:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32657</strong></p>
  <p>Hydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser context of Hydra and execute authenticated HTTP requests. The abused feature allows Nix builds to specify files that Hydra serves to clients. One use of this functionality is serving NixOS `.iso` files. The issue is only with html files served by Hydra. The issue has been patched…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52644 – In the Linux kernel, the following vulnerability has been resolved:

wifi: b43: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52644</guid>
    <pubDate>Wed, 17 Apr 2024 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52644</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: b43: Stop/wake correct queue in DMA Tx path when QoS is disabled  When QoS is disabled, the queue priority value will not map to the correct ieee80211 queue since there is only one queue. Stop/wake queue 0 when QoS is disabled to prevent trying to stop/wake a non-existent queue and failing to stop/wake the actual queue ins…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36476 – calamares-nixos-extensions provides Calamares branding and modules for NixOS, a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36476</guid>
    <pubDate>Thu, 29 Jun 2023 01:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36476</strong></p>
  <p>calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares installer, with an unencrypted `/boot`, on either non-UEFI systems or with a LUKS partition different from `/` have their LUKS key file in `/boot` as a plaintext CPIO archive atta…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-11501 – NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Val...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11501</guid>
    <pubDate>Thu, 20 Jul 2017 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-11501</strong></p>
  <p>NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to connect to the LDAP server with users.ldap.useTLS, peer verification will be unconditionally disabled in /etc/ldap.conf.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7412 – NixOS 17.03 before 17.03.887 has a world-writable Docker socket, which allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7412</guid>
    <pubDate>Tue, 04 Apr 2017 00:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7412</strong></p>
  <p>NixOS 17.03 before 17.03.887 has a world-writable Docker socket, which allows local users to gain privileges by executing docker commands.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7412">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
