# News on Lix

Recent content in News on Lix

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## An exploitable integer overflow in Lix (CVE-2026-44028)

DevFeed: [An exploitable integer overflow in Lix (CVE-2026-44028)](<https://devfeed.tech/articles/an-exploitable-integer-overflow-in-lix-cve-2026-44028-31380.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/>)

Published: 2026-05-05T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Nix](<https://devfeed.tech/topics/nix.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Lix has an integer-overflow vulnerability assigned CVE-2026-44028. The issue can enable an out-of-bounds write through a specially crafted NAR archive, with exploitability depending on build type and ASLR defenses. Fixed versions are Lix 2.93.4, 2.94.2, and 2.95.2, and users are advised to update.

### Source excerpt

Security researchers have found a security issue in Lix. This issue has been assigned CVE-2026-44028. Important note : The issues are different between Lix and CppNix but it seems there was confusion in MITRE who emitted the CVE and copied the wrong information which should have gone into the CppNix CVE, we are trying to update the CVE metadata.

## Announcing Lix 2.95 "Kakigōri"

DevFeed: [Announcing Lix 2.95 "Kakigōri"](<https://devfeed.tech/articles/announcing-lix-2-95-kakigori-31379.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2026-03-25-lix-2.95-release/>)

Published: 2026-03-25T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [Cap'n Proto](<https://devfeed.tech/topics/capnproto.md>), [Remote Procedure Call (RPC)](<https://devfeed.tech/topics/rpc.md>), [Nix](<https://devfeed.tech/topics/nix.md>)

Tags: [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [performance](<https://devfeed.tech/tags/performance.md>), [release](<https://devfeed.tech/tags/release.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

The Lix team announces version 2.95, "Kakigōri," a major release focused on bug fixes, quality-of-life improvements, documentation, performance, and continued integration with the Cap'n Proto RPC runtime. The article also describes upgrade guidance and ongoing work toward additional RPC protocols.

### Source excerpt

We at the Lix team are proud to announce our sixth major release, version 2.95 "Kakigōri". This release focuses on long-awaited bugfixes, quality-of-life improvements, documentation, performance improvements and continued integration of Lix with the Cap'n'Proto remote procedure call runtime to replace the previous bespoke implementation.

## Announcing Lix 2.94 "Açaí na tigela"

DevFeed: [Announcing Lix 2.94 "Açaí na tigela"](<https://devfeed.tech/articles/announcing-lix-2-94-acai-na-tigela-31378.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-11-18-lix-2.94-release/>)

Published: 2025-11-18T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Remote Procedure Call (RPC)](<https://devfeed.tech/topics/rpc.md>), [Cap'n Proto](<https://devfeed.tech/topics/capnproto.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [hooks](<https://devfeed.tech/topics/hooks.md>), [Logging](<https://devfeed.tech/topics/logging.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [hooks](<https://devfeed.tech/tags/hooks.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [logging](<https://devfeed.tech/tags/logging.md>), [performance](<https://devfeed.tech/tags/performance.md>), [release](<https://devfeed.tech/tags/release.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

Lix 2.94 is a major release focused on bug fixes, quality-of-life and performance improvements, with initial integration of the Cap'n Proto RPC runtime to replace a bespoke implementation. It includes Cap'n Proto protocol definitions for build hooks and logging, enabling multiple build hook processes to wait concurrently.

### Source excerpt

We at the Lix team are proud to announce our fifth major release, version 2.94 "Açaí na tigela". This release focuses on bugfixes, quality-of-life improvements, performance improvements and started integrating Lix with the Cap'n'Proto remote procedure call runtime, in order to replace the previous bespoke implementation.

## LixCon in 2026

DevFeed: [LixCon in 2026](<https://devfeed.tech/articles/lixcon-in-2026-31377.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-11-05-lixcon-2026/>)

Published: 2025-11-05T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [announce](<https://devfeed.tech/tags/announce.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [conference](<https://devfeed.tech/tags/conference.md>), [development](<https://devfeed.tech/tags/development.md>), [event](<https://devfeed.tech/tags/event.md>), [hacking](<https://devfeed.tech/tags/hacking.md>)

### AI overview

LixCon 2026 will take place in Paris from April 17 to 19, 2026. The event will focus on the Lix interpreter and its internals, with talks on the first day followed by hands-on development, discussions, and collaboration. Attendance will be limited to 200 people.

### Source excerpt

LixCon 2026 - this coming April, in Paris We won't bury the lede: we're super excited to announce that our first LixCon will take place from the 17th to 19th of April, 2026, in Paris!

## Lix Announces New Governance Model and Zulip Communications Space

DevFeed: [Lix Announces New Governance Model and Zulip Communications Space](<https://devfeed.tech/articles/meta-news-on-lix-in-october-2025-31376.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-10-13-meta-lix-news/>)

Published: 2025-10-13T00:00:00Z

Content type: news

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [communications](<https://devfeed.tech/topics/communications.md>), [Gerrit](<https://devfeed.tech/topics/gerrit.md>), [Matrix](<https://devfeed.tech/topics/matrix-org.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [communications](<https://devfeed.tech/tags/communications.md>), [community](<https://devfeed.tech/tags/community.md>), [gerrit](<https://devfeed.tech/tags/gerrit.md>), [governance](<https://devfeed.tech/tags/governance.md>), [matrix](<https://devfeed.tech/tags/matrix.md>), [news](<https://devfeed.tech/tags/news.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Lix announces a new governance model with core, committer, and community teams. The project is also adopting Zulip for high-bandwidth discussions while continuing to use Matrix for chats and announcements.

### Source excerpt

As Lix continues to evolve, we're excited to share some major updates that mark a new chapter in our journey. This blog post is the first of its kind: we want to give you a deeper look into the decisions, plans, and developments shaping the future of Lix.

## Critical correctness bug in Lix

DevFeed: [Critical correctness bug in Lix](<https://devfeed.tech/articles/critical-correctness-bug-in-lix-31375.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-06-27-lix-critical-bug/>)

Published: 2025-06-27T00:00:00Z

Content type: news

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [bug](<https://devfeed.tech/topics/bug.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Nix](<https://devfeed.tech/topics/nix.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Deployment Tools](<https://devfeed.tech/topics/deployment-tools.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [critical](<https://devfeed.tech/tags/critical.md>), [incident](<https://devfeed.tech/tags/incident.md>), [linux](<https://devfeed.tech/tags/linux.md>)

### AI overview

A critical regression in Lix versions 2.91.2, 2.92.2, and 2.93.1 can cause missing or silently invalidated store paths during derivation builds. The incident has been mitigated; versions 2.91.3, 2.92.3, and 2.93.2 are identified as unaffected, with recovery guidance provided.

### Source excerpt

This incident has been mitigated. This post will be updated with pointers on how to close it. The Lix team remains available over all support channels to help recovering any system affected by it.

## Fixes for five Lix CVEs

DevFeed: [Fixes for five Lix CVEs](<https://devfeed.tech/articles/fixes-for-five-lix-cves-31374.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-06-24-lix-cves/>)

Published: 2025-06-24T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [bug](<https://devfeed.tech/topics/bug.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Lix reports five security issues assigned CVE numbers and announces fixes in Lix 2.91, 2.92, and 2.93. The article summarizes the vulnerability chain, including temporary-directory handling and a recursive deletion bug.

### Source excerpt

Security researchers have found five security issues in Lix. These issues were assigned CVE numbers: CVE-2025-46415 CVE-2025-46416 CVE-2025-52991 CVE-2025-52992 CVE-2025-52993 We have release updates to Lix 2.

## Announcing Lix 2.93 "Bici Bici"

DevFeed: [Announcing Lix 2.93 "Bici Bici"](<https://devfeed.tech/articles/announcing-lix-2-93-bici-bici-31373.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-05-06-lix-2.93-release/>)

Published: 2025-05-06T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [Nix](<https://devfeed.tech/topics/nix.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>), [deprecated](<https://devfeed.tech/topics/deprecated.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [asynchronous](<https://devfeed.tech/tags/asynchronous.md>), [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [release](<https://devfeed.tech/tags/release.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

The Lix team announces version 2.93, a major release focused on bug fixes and continued integration with the KJ asynchronous runtime. The release also deprecates CR/CRLF line endings and literal NUL bytes in Nix expressions, which produce errors by default.

### Source excerpt

We at the Lix team are proud to announce our fourth major release, version 2.93 "Bici Bici". This release focuses on bugfixes and continues integrating Lix with the KJ asynchronous runtime, in order to replace the previous bespoke implementation.

## Announcing Lix 2.92 "Bombe glacée"

DevFeed: [Announcing Lix 2.92 "Bombe glacée"](<https://devfeed.tech/articles/announcing-lix-2-92-bombe-glacee-31372.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-01-18-lix-2.92-release/>)

Published: 2025-01-18T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [async](<https://devfeed.tech/topics/async.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [deprecated](<https://devfeed.tech/topics/deprecated.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [async](<https://devfeed.tech/tags/async.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [release](<https://devfeed.tech/tags/release.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

Lix 2.92 is a major release focused on evolving its evaluator and store, improving evaluator speed, and removing rarely used and troublesome Nix language features. It also reworks the daemon with asynchronous C++ code and begins deprecating problematic language features.

### Source excerpt

We at the Lix team are proud to announce our third major release, version 2.92 "Bombe glacée". This release focuses on evolution work of the evaluator and store in order to be able to replace the Nix store protocol, to make the evaluator faster, and to remove rarely-used and troublesome features of the Nix language.

## Lix installations upgrading to macOS Sequoia require manual repair

DevFeed: [Lix installations upgrading to macOS Sequoia require manual repair](<https://devfeed.tech/articles/lix-installations-upgrading-to-macos-sequoia-require-manual-repair-31371.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2024-09-15-sequoia-intervention/>)

Published: 2024-09-15T00:00:00Z

Content type: article

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [macOS](<https://devfeed.tech/topics/macos.md>), [Nix](<https://devfeed.tech/topics/nix.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>)

Tags: [installation](<https://devfeed.tech/tags/installation.md>), [macos](<https://devfeed.tech/tags/macos.md>), [os](<https://devfeed.tech/tags/os.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

The article explains that upgrading macOS installations of Lix and Nix to macOS Sequoia can cause builds to fail because Apple claims user IDs used by the default Nix installation. It describes using the installer's repair functionality, including before the upgrade.

### Source excerpt

macOS Sequoia release day is almost upon us, and that means all your Lix and Nix installations on macOS are going to break when you upgrade your OS.

## Announcing Lix 2.91 "Dragon's Breath"

DevFeed: [Announcing Lix 2.91 "Dragon's Breath"](<https://devfeed.tech/articles/announcing-lix-2-91-dragon-s-breath-31370.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2024-08-12-lix-2.91-release/>)

Published: 2024-08-12T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [bug](<https://devfeed.tech/tags/bug.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [performance](<https://devfeed.tech/tags/performance.md>), [release](<https://devfeed.tech/tags/release.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

The Lix team announces version 2.91, "Dragon's Breath," a major release of the Nix implementation. The release includes bug fixes, performance improvements, refactorings, design changes, user-facing updates, and an experimental pipe operator.

### Source excerpt

We at the Lix team are proud to announce our second major release, version 2.91 "Dragon's Breath". This release contains unspecified bug fixes and performance improvements--no of course we will tell you what is in it.

## Announcing Lix 2.90 "Vanilla Ice Cream"

DevFeed: [Announcing Lix 2.90 "Vanilla Ice Cream"](<https://devfeed.tech/articles/announcing-lix-2-90-vanilla-ice-cream-31369.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2024-07-10-lix-2.90-release/>)

Published: 2024-07-10T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [implementation](<https://devfeed.tech/topics/implementation.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [bug-fixes](<https://devfeed.tech/tags/bug-fixes.md>), [features](<https://devfeed.tech/tags/features.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [release](<https://devfeed.tech/tags/release.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

The Lix team announces Lix 2.90, its first release. The release focuses on reliability and foundations while adding Lix-specific features, performance improvements, more detailed error reporting, debugger fixes, and other user experience improvements.

### Source excerpt

We at the Lix team are proud to announce our first release, version 2.90 "Vanilla Ice Cream". This release focuses on foundations and reliability, but nevertheless contains several small but exciting user-facing features that are exclusive to Lix.