# An exploitable integer overflow in Lix (CVE-2026-44028)

DevFeed: [An exploitable integer overflow in Lix (CVE-2026-44028)](<https://devfeed.tech/articles/an-exploitable-integer-overflow-in-lix-cve-2026-44028-31380.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/>)

Published: 2026-05-05T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Nix](<https://devfeed.tech/topics/nix.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>)

## AI overview

Lix has an integer-overflow vulnerability assigned CVE-2026-44028. The issue can enable an out-of-bounds write through a specially crafted NAR archive, with exploitability depending on build type and ASLR defenses. Fixed versions are Lix 2.93.4, 2.94.2, and 2.95.2, and users are advised to update.

## Source excerpt

Security researchers have found a security issue in Lix. This issue has been assigned CVE-2026-44028. Important note : The issues are different between Lix and CppNix but it seems there was confusion in MITRE who emitted the CVE and copied the wrong information which should have gone into the CppNix CVE, we are trying to update the CVE metadata.