Skip to content
Fedora 43 Nix 2.31.4 Serious Privilege Escalation Flaw GHSA-g3g9-5vj6

Fedora 43 Nix 2.31.4 Serious Privilege Escalation Flaw GHSA-g3g9-5vj6

Linuxsecurity •LinuxSecurity Advisories • April 17, 2026

Nix is a purely functional package manager. It allows multiple versions of a package to be installed side-by-side, ensures that dependency specifications are complete, supports atomic upgrades and rollbacks, allows non-root users to install software, and has many other features. It is the basis of the NixOS Linux distribution, but it can be used equally well under other Unix systems. See the README.fedora.md file for setup instructions. Update Information : update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860):

Nix is a purely functional package manager.

It allows multiple versions of a package to be installed side-by-side,

ensures that dependency specifications are complete,

supports atomic upgrades and rollbacks,

allows non-root users to install software, and has many other features.

It is the basis of the NixOS Linux distribution,

but it can be used equally well under other Unix systems.

See the README.fedora.md file for setup instructions.

update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860):

* Wed Apr 8 2026 Jens Petersen - 2.31.4-1 - update to 2.31.4 - fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) * Wed Apr 8 2026 Jens Petersen - 2.31.3-2 - sync readme/gating/tests improvements from rawhide/f44 - document nixGL - enable gating on tier0 and install CI tests

* Wed Apr 8 2026 Jens Petersen - 2.31.4-1 - update to 2.31.4 - fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) * Wed Apr 8 2026 Jens Petersen - 2.31.3-2 - sync readme/gating/tests improvements from rawhide/f44 - document nixGL - enable gating on tier0 and install CI tests

[ 1 ] Bug #2456893 - CVE-2026-39860 nix: privilege escalation via symlink following during output registration [fedora-all]

[ 1 ] Bug #2456893 - CVE-2026-39860 nix: privilege escalation via symlink following during output registration [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6c1a1c78c1' at the command line. For more information, refer to the dnf documentation available at

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6c1a1c78c1' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities