Debian Package Tracker
Register | Log in
Subscribe

nix

Choose email to subscribe with

general
  • source: nix (main)
  • version: 2.34.8+dfsg-1
  • maintainer: Jordan Justen (DMD)
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.3.7+dfsg1-1
  • oldstable: 2.8.0-1.1
  • stable: 2.26.3+dfsg-1
  • testing: 2.34.8+dfsg-1
  • unstable: 2.34.8+dfsg-1
versioned links
  • 2.3.7+dfsg1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.8.0-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.26.3+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.34.8+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • nix-bin (2 bugs: 0, 2, 0, 0)
  • nix-setup-systemd (2 bugs: 0, 1, 1, 0)
action needed
A new upstream version is available: 2.35.2 high
A new upstream version 2.35.2 is available, you should consider packaging it.
Created: 2026-07-17 Last update: 2026-08-14 04:30
Marked for autoremoval on 18 September due to toml11: #1143713 high
Version 2.34.8+dfsg-1 of nix is marked for autoremoval from testing on Fri 18 Sep 2026. It depends (transitively) on toml11, affected by #1143713. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-08-12 Last update: 2026-08-14 03:33
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2024-36050: Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
Created: 2024-03-13 Last update: 2026-08-02 20:32
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2024-36050: Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
Created: 2025-08-09 Last update: 2026-08-02 20:32
lintian reports 96 warnings normal
Lintian reports 96 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-26 Last update: 2026-04-26 07:00
4 low-priority security issues in trixie low

There are 4 open security issues in trixie.

4 issues left for the package maintainer to handle:
  • CVE-2024-36050: (postponed; to be fixed through a stable update) Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
  • CVE-2026-39860: (needs triaging) Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the build chroot. A symlink, pointing to an arbitrary location in the filesystem, could be created by the derivation builder at that path. During output registration, the Nix process (running in the host mount namespace) would follow that symlink and overwrite the destination with the derivation's output contents. In multi-user installations, this allows all users able to submit builds to the Nix daemon (allowed-users - defaulting to all users) to gain root privileges by modifying sensitive files. This vulnerability is fixed in 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, and 2.28.6.
  • CVE-2026-44028: (needs triaging) An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed. This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0).
  • CVE-2026-44029: (needs triaging) An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-08-09 Last update: 2026-08-02 20:32
debian/patches: 6 patches to forward upstream low

Among the 6 debian patches available in version 2.34.8+dfsg-1 of the package, we noticed the following issues:

  • 6 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-07-13 06:02
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-07-15] nix 2.34.8+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-13] Accepted nix 2.34.8+dfsg-1 (source) into unstable (Jordan Justen)
  • [2026-04-28] nix 2.34.6+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-25] Accepted nix 2.34.6+dfsg-1 (source) into unstable (Jordan Justen)
  • [2026-04-01] nix 2.34.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-24] Accepted nix 2.34.3+dfsg-1 (source) into unstable (Jordan Justen)
  • [2026-03-16] nix 2.32.5+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-08] Accepted nix 2.32.5+dfsg-2 (source) into unstable (Jordan Justen)
  • [2026-02-24] nix 2.32.5+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-21] Accepted nix 2.32.5+dfsg-1 (source) into unstable (Jordan Justen)
  • [2025-04-12] nix 2.26.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-10] Accepted nix 2.26.3+dfsg-1 (source) into unstable (Jordan Justen)
  • [2025-03-08] nix 2.24.12+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-06] Accepted nix 2.24.12+dfsg-1 (source) into unstable (Jordan Justen)
  • [2025-01-16] Accepted nix 2.25.4+dfsg-1 (source) into experimental (Jordan Justen)
  • [2024-11-01] nix 2.24.9+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-10-29] Accepted nix 2.24.9+dfsg-2 (source) into unstable (Jordan Justen)
  • [2024-10-11] Accepted nix 2.24.9+dfsg-1 (source) into unstable (Jordan Justen)
  • [2024-10-03] nix 2.24.8+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-29] Accepted nix 2.24.8+dfsg-1 (source) into unstable (Jordan Justen)
  • [2024-08-12] nix 2.23.3+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-08-09] Accepted nix 2.23.3+dfsg-2 (source) into unstable (Jordan Justen)
  • [2024-07-22] nix 2.23.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-20] Accepted nix 2.23.3+dfsg-1 (source) into unstable (Jordan Justen)
  • [2024-06-08] nix 2.22.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-06] Accepted nix 2.22.1+dfsg-1 (source) into unstable (Jordan Justen)
  • [2023-10-20] nix 2.18.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-17] Accepted nix 2.18.1+dfsg-1 (source) into unstable (Jordan Justen)
  • [2023-10-15] nix 2.17.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-13] Accepted nix 2.17.1+dfsg-1 (source) into unstable (Jordan Justen)
  • 1
  • 2
bugs [bug history graph]
  • all: 7
  • RC: 0
  • I&N: 6
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 96)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.34.8+dfsg-1build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing