Nix 2.24 is vulnerable to (remote) privilege escalation
puckipedia.com
Nix 2.24 is vulnerable to (remote) privilege escalation
1–10 of 81 posts
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#2It's on Nix to meet the disclosure timeline. Missing that is Nix being irresponsible, not puck.
I see this often, and it's not a good look when people would rather punish the reporter of an issue rather than the organization that was given plenty of time to do something about it.
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#3Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#4I don't get why someone who responded to this calls this something other than responsible disclosure. puck clearly writes, "at this point the disclosure timeline has passed". It's on Nix to meet the disclosure timeline. Missing that is Nix being irresponsible, not puck. I see this often, and it's not a good look when people would rather punish the reporter of an issue rather than the organization that was given plent…
One week doesn't seem like "plenty of time" to me. The guy who ack'd the initial report and created the vulnerability tracker in GitHub was on vacation.
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#5It seems like a binary cache can already get root on your system - it is serving you binaries to run, often as root. Don't authorize a binary cache you don't trust.
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#6To use lix instead of nix, set `nix.package = pkgs.lix` in your NixOS/home-manager configurations.
[1]: https://lix.systems/
[2]: https://mastodon.delroth.net/@delroth/113110218127456491
[3]: https://lobste.rs/s/ixb3v7/nix_2_24_is_vulnerable_remote_pri...
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#7lix [1] might be less affected. Pierre Bourdon noticed that lix refactored surrounding code 4 months ago [2], and a comment claims that this Lix commit at least patched a different vulnerability GHSA-wf4c-57rh-9pjg [3]. To use lix instead of nix, set `nix.package = pkgs.lix` in your NixOS/home-manager configurations. [1]: https://lix.systems/ [2]: https://mastodon.delroth.net/@delroth/113110218127456491 [3]: https://…
I mean as an user, why would I want to use it (besides avoiding this vulnerability)
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#8I don't get why someone who responded to this calls this something other than responsible disclosure. puck clearly writes, "at this point the disclosure timeline has passed". It's on Nix to meet the disclosure timeline. Missing that is Nix being irresponsible, not puck. I see this often, and it's not a good look when people would rather punish the reporter of an issue rather than the organization that was given plent…
> the organization that was given plenty of time One week doesn't seem like "plenty of time" to me. The guy who ack'd the initial report and created the vulnerability tracker in GitHub was on vacation.
Re: Nix 2.24 is vulnerable to (remote) privilege escalation
#9I don't get why someone who responded to this calls this something other than responsible disclosure. puck clearly writes, "at this point the disclosure timeline has passed". It's on Nix to meet the disclosure timeline. Missing that is Nix being irresponsible, not puck. I see this often, and it's not a good look when people would rather punish the reporter of an issue rather than the organization that was given plent…
> the organization that was given plenty of time One week doesn't seem like "plenty of time" to me. The guy who ack'd the initial report and created the vulnerability tracker in GitHub was on vacation.
Spin it how you like, but the "we're too important to respond" shtick is old and tired.