CVE-2025-46415

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-46415
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-46415.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-46415
Related
Published
2025-06-27T14:15:37Z
Modified
2025-07-01T16:32:12.039417Z
Summary
[none]
Details

A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

References

Affected packages

Debian:11 / guix

Package

Name
guix
Purl
pkg:deb/debian/guix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.0-4
1.2.0-4+deb11u1
1.2.0-4+deb11u2
1.2.0-4+deb11u3
1.3.0~rc1-1
1.3.0-1
1.3.0-2
1.3.0-3
1.3.0-4
1.3.0-5
1.3.0+26720.a2e4e-1
1.3.0+26756.c07b5-1
1.3.0+26756.c07b5-2
1.4.0~rc1-1
1.4.0~rc1-2
1.4.0~rc2-1
1.4.0-1
1.4.0-2
1.4.0-3
1.4.0-4
1.4.0-5
1.4.0-6
1.4.0-7
1.4.0-8
1.4.0-9
1.4.0+154709.ab1b557d8f3-1
1.4.0+154710+ab1b5-1
1.4.0+154710+ab1b5-2
1.4.0+154928+f1810-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / guix

Package

Name
guix
Purl
pkg:deb/debian/guix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.4.0-3
1.4.0-3+deb12u1
1.4.0-3+deb12u2
1.4.0-4
1.4.0-5
1.4.0-6
1.4.0-7
1.4.0-8
1.4.0-9
1.4.0+154709.ab1b557d8f3-1
1.4.0+154710+ab1b5-1
1.4.0+154710+ab1b5-2
1.4.0+154928+f1810-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / guix

Package

Name
guix
Purl
pkg:deb/debian/guix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.4.0-3
1.4.0-4
1.4.0-5
1.4.0-6
1.4.0-7
1.4.0-8
1.4.0-9
1.4.0+154709.ab1b557d8f3-1
1.4.0+154710+ab1b5-1
1.4.0+154710+ab1b5-2
1.4.0+154928+f1810-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}