CVE-2026-64846 | NixOS Nix up to 2.34.x LocalStore Restore Path writeFile toctou

SecurityVulns

A vulnerability, which was classified as problematic, was found in NixOS Nix up to 2.34.x. Impacted is the function writeFile of the component LocalStore Restore Path. Such manipulation leads to time-of-check time-of-use.

This vulnerability is traded as CVE-2026-64846. An attack has to be approached locally. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More