CVE-2024-27297 | NixOS nix up to 2.3.17/2.18.1/2.19.3/2.20.4 on Linux Unix Domain Socket toctou (GHSA-2ffj-w4mj-pg37 / Nessus ID 242201)
A vulnerability was found in NixOS nix up to 2.3.17/2.18.1/2.19.3/2.20.4 on Linux. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Unix Domain Socket Handler. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2024-27297. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.