A coordinated disclosure detailed a local privilege escalation flaw in the Nix and Lix package manager daemons that can let a local user execute arbitrary code as root in multi-user deployments. The primary issue, tracked as CVE-2026-44028, stems from unbounded recursion in the Nix Archive (NAR) directory parser running on a coroutine stack without a guard page, creating a stack-to-heap overflow condition that can lead to heap corruption. Exploitation requires access to the daemon interface, typically through allowed-users or trusted-users, and a crafted deeply nested NAR payload; the attack is considered most relevant where the daemon runs as root and user access is broadly permitted.
Maintainers released fixes across multiple supported branches, including Nix 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7, and Lix 2.93.4, 2.94.2, and 2.95.2. The patches add recursion depth limits, guard pages for coroutine stacks, bounds checks for file names and symlink targets, and worker crash limits intended to make ASLR brute forcing harder. The disclosure also distinguished this flaw from separate Nix issues, including CVE-2026-44029 / GHSA-gr92-w2r5-qw5p, and stated that Guix is not affected; remote substituters were described as a limited practical attack path because they cannot reliably generate enough attempts to exploit the bug.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The disclosure stated that Nix fixed the issue in versions 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7, while Lix fixed it in versions 2.93.4, 2.94.2, and 2.95.2. Upstream mitigations included recursion depth limits, guard pages for coroutine stacks, bounds checks, and a worker crash limit.
A coordinated disclosure described local privilege escalation vulnerabilities in the Nix and Lix daemon implementations that could let a local user with daemon access execute arbitrary code as the daemon user, typically root in multi-user installations. The Lix issue was identified as CVE-2026-44028, and the disclosure noted related but distinct Nix advisories and CVE-2026-44029.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.