Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module
captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localhost traffic from privileged services...). This vulnerability is fixed in 25.11 and 26.05.
References
-
https://github.com/NixOS/nixpkgs/security/advisories/GHSA-wc3r-c66x-8xmc x_refsource_CONFIRM
-
https://github.com/NixOS/nixpkgs/pull/487775 x_refsource_MISC
-
https://github.com/NixOS/nixpkgs/pull/487779 x_refsource_MISC
-
https://github.com/NixOS/nixpkgs/security/advisories/GHSA-wc3r-c66x-8xmc x_refsource_CONFIRM
-
https://github.com/NixOS/nixpkgs/pull/487775 x_refsource_MISC
-
https://github.com/NixOS/nixpkgs/pull/487779 x_refsource_MISC
Affected products
- ==<= 25.05
Matching in nixpkgs
pkgs.manual
None
pkgs.metrics
None
pkgs.tarball
Source distribution
-
nixos-unstable 25.11pre1234.abcdef
- nixpkgs-unstable 26.05pre1234.abcdef
- nixos-unstable-small 26.05pre1234.abcdef
-
nixos-25.11 25.11pre1234.abcdef
- nixpkgs-25.11-darwin 25.11pre1234.abcdef
pkgs.unstable
Release-critical builds for the Nixpkgs unstable channel
-
nixos-unstable 25.11pre1234.abcdef
- nixpkgs-unstable 26.05pre1234.abcdef
- nixos-unstable-small 26.05pre1234.abcdef
-
nixos-25.11 25.11pre1234.abcdef
- nixpkgs-25.11-darwin 25.11pre1234.abcdef
pkgs.lib-tests
None
-
nixos-unstable -
pkgs.nixpkgs-fmt
Nix code formatter for nixpkgs
pkgs.nixpkgs-vet
Tool to vet (check) Nixpkgs, including its pkgs/by-name directory
pkgs.nixpkgs-lint
A utility for Nixpkgs contributors to check Nixpkgs for common errors
pkgs.darwin-tested
Release-critical builds for the Nixpkgs darwin channel
-
nixos-unstable 25.11pre1234.abcdef
- nixpkgs-unstable 26.05pre1234.abcdef
- nixos-unstable-small 26.05pre1234.abcdef
-
nixos-25.11 25.11pre1234.abcdef
- nixpkgs-25.11-darwin 25.11pre1234.abcdef
pkgs.dhall-nixpkgs
Convert Dhall projects to Nix packages
pkgs.nixpkgs-track
Track where Nixpkgs pull requests have reached
pkgs.nixpkgs-manual
None
pkgs.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.release-checks
None
pkgs.nixpkgs-pytools
Tools for removing the tedious nature of creating nixpkgs derivations
pkgs.tests.lib-tests
None
pkgs.nixpkgs-hammering
Set of nit-picky rules that aim to point out and explain common mistakes in nixpkgs package pull requests
-
nixos-unstable 0-unstable-2025-02-09
- nixpkgs-unstable 0-unstable-2025-09-10
- nixos-unstable-small 0-unstable-2025-09-10
-
nixos-25.11 0-unstable-2025-09-10
- nixpkgs-25.11-darwin 0-unstable-2025-09-10
pkgs.nixpkgs-reviewFull
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.nixpkgs-lint-community
Fast semantic linter for Nix using tree-sitter
pkgs.tests.pkgs-lib.formats
None
pkgs.nixpkgs-openjdk-updater
Updater for Nixpkgs OpenJDK packages
pkgs.python312Packages.nixpkgs
Allows to `from nixpkgs import` stuff in interactive Python sessions
-
nixos-unstable 0.2.4
pkgs.python313Packages.nixpkgs
Allows to `from nixpkgs import` stuff in interactive Python sessions
-
nixos-unstable 0.2.4
pkgs.haskellPackages.dhall-nixpkgs
Convert Dhall projects to Nix packages
pkgs.lixPackageSets.git.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.python312Packages.nixpkgs-pytools
Tools for removing the tedious nature of creating nixpkgs derivations
-
nixos-unstable 1.3.0
pkgs.python313Packages.nixpkgs-pytools
Tools for removing the tedious nature of creating nixpkgs derivations
pkgs.python314Packages.nixpkgs-pytools
Tools for removing the tedious nature of creating nixpkgs derivations
pkgs.tests.trivial-builders.references
None
pkgs.haskellPackages.distribution-nixpkgs
Types and functions to manipulate the Nixpkgs distribution
pkgs.lixPackageSets.latest.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.lixPackageSets.stable.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.lixPackageSets.git.nixpkgs-reviewFull
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.lixPackageSets.lix_2_90.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
-
nixos-unstable 3.4.0
pkgs.lixPackageSets.lix_2_92.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
-
nixos-unstable 3.4.0
pkgs.lixPackageSets.lix_2_93.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
-
nixos-unstable 3.4.0
pkgs.lixPackageSets.lix_2_94.nixpkgs-review
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.python312Packages.nixpkgs-plugin-update
Library for updating plugin collections in Nixpkgs
pkgs.python313Packages.nixpkgs-plugin-update
Library for updating plugin collections in Nixpkgs
pkgs.python314Packages.nixpkgs-plugin-update
Library for updating plugin collections in Nixpkgs
pkgs.lixPackageSets.stable.nixpkgs-reviewFull
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.lixPackageSets.lix_2_94.nixpkgs-reviewFull
Review pull-requests on https://github.com/NixOS/nixpkgs
pkgs.python312Packages.nixpkgs-updaters-library
Boilerplate-less updater library for Nixpkgs ecosystems
pkgs.python313Packages.nixpkgs-updaters-library
Boilerplate-less updater library for Nixpkgs ecosystems
pkgs.python314Packages.nixpkgs-updaters-library
Boilerplate-less updater library for Nixpkgs ecosystems
-
nixos-unstable B4dM4n-nixpkgs-fmt-0.0.1
- nixpkgs-unstable B4dM4n-nixpkgs-fmt-0.0.1
- nixos-unstable-small B4dM4n-nixpkgs-fmt-0.0.1
-
nixos-25.11 B4dM4n-nixpkgs-fmt-0.0.1
- nixpkgs-25.11-darwin B4dM4n-nixpkgs-fmt-0.0.1
pkgs.haskellPackages.distribution-nixpkgs-unstable
Types and functions to manipulate the Nixpkgs distribution
-
nixos-unstable -
- nixpkgs-unstable 1.7.1.1-unstable-2026-01-25
- nixos-unstable-small 1.7.1.1-unstable-2026-01-25
-
nixos-25.11 1.7.1.1-unstable-2025-11-20
- nixpkgs-25.11-darwin 1.7.1.1-unstable-2025-11-20
Package maintainers
-
@Gabriella439 Gabriella Gonzalez <GenuineGabriella@gmail.com>
-
@sternenseemann Lukas Epple <sternenseemann@systemli.org>
-
@figsoda figsoda <figsoda@pm.me>
-
@Mic92 Jörg Thalheim <joerg@thalheim.io>
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@edolstra Eelco Dolstra <edolstra+nixpkgs@gmail.com>
-
@Artturin Artturi N <artturin@artturin.com>
-
@emilazy Emily <nixpkgs@emily.moe>
-
@uncenter uncenter <uncenter@uncenter.dev>
-
@isabelroses Isabel Roses <isabel@isabelroses.com>
-
@matthiasbeyer Matthias Beyer <mail@beyermatthias.de>
-
@philiptaron Philip Taron <philip.taron@gmail.com>
-
@willbush Will Bush <git@willbush.dev>
-
@t184256 Alexander Sosedkin <monk@unboiled.info>
-
@PerchunPak Perchun Pak <nixpkgs@perchun.it>
-
@roberth Robert Hensing <nixpkgs@roberthensing.nl>
-
@ShamrockLee Yueh-Shun Li <shamrocklee@posteo.net>
-
@mdaniels5757 Michael Daniels <nix@mdaniels.me>
-
@khaneliman Austin Horstman <khaneliman12@gmail.com>
-
@teto Matthieu Coudron <mcoudron@hotmail.com>