Back Linuxsecurity Fedora 42 Nix Critical Privilege Escalation Fix GHSA-g3g9-5vj6
Nix is a purely functional package manager. It allows multiple versions of a package to be installed side-by-side, ensures that dependency specifications are complete, supports atomic upgrades and rollbacks, allows non-root users to install software, and has many other features. It is the basis of the NixOS Linux distribution, but it can be used equally well under other Unix systems. See the README.fedora.md file for setup instructions. Update Information : update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860)
Nix is a purely functional package manager.
It allows multiple versions of a package to be installed side-by-side,
ensures that dependency specifications are complete,
supports atomic upgrades and rollbacks,
allows non-root users to install software, and has many other features.
It is the basis of the NixOS Linux distribution,
but it can be used equally well under other Unix systems.
See the README.fedora.md file for setup instructions.
update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860)
* Wed Apr 8 2026 Jens Petersen - 2.31.4-1 - update to 2.31.4 - fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) * Wed Apr 8 2026 Jens Petersen - 2.31.3-2 - sync readme/gating/tests improvements from rawhide/f44 - document nixGL - enable gating on tier0 and install CI tests
* Wed Apr 8 2026 Jens Petersen - 2.31.4-1 - update to 2.31.4 - fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) * Wed Apr 8 2026 Jens Petersen - 2.31.3-2 - sync readme/gating/tests improvements from rawhide/f44 - document nixGL - enable gating on tier0 and install CI tests
[ 1 ] Bug #2456893 - CVE-2026-39860 nix: privilege escalation via symlink following during output registration [fedora-all]
[ 1 ] Bug #2456893 - CVE-2026-39860 nix: privilege escalation via symlink following during output registration [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-02fa328deb' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-02fa328deb' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
