« Volver al listado

CVE-2026-44028

Estado: AplazadaAlta (7.5)—

An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed.

Leer descripción completaMostrar menos

This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L) con PR:L sin interacción del usuario → T1068. Stack-to-heap overflow permitiendo ejecución arbitraria como root (daemon) → T1059. Escalada de privilegios implícita (ejecución como root) → T1548.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44028",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44028",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-05T14:03:11.111278Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1.1
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "NixOS",
          "product": "Nix",
          "versions": [
            {
              "status": "affected",
              "version": "2.24.4",
              "lessThan": "2.28.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.29.0",
              "lessThan": "2.29.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.30.0",
              "lessThan": "2.30.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.31.0",
              "lessThan": "2.31.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.32.0",
              "lessThan": "2.32.8",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.33.0",
              "lessThan": "2.33.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.34.0",
              "lessThan": "2.34.7",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Lix Project",
          "product": "Lix",
          "versions": [
            {
              "status": "affected",
              "version": "2.93.0",
              "lessThan": "2.93.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.94.0",
              "lessThan": "2.94.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.95.0",
              "lessThan": "2.95.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-05T01:16:06.983",
  "references": [
    {
      "url": "https://discourse.nixos.org/t/security-advisory-local-privilege-escalation-in-lix-and-nix/77407",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2026/05/04/32",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2026/05/04/33",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-674"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed. This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0)."
    }
  ],
  "lastModified": "2026-06-17T10:50:12.857",
  "sourceIdentifier": "cve@mitre.org"
}