CVE-2025-59378

Name
CVE-2025-59378
Description
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://codeberg.org/guix/guix/commit/1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45
cve@mitre.org https://guix.gnu.org/en/blog/2025/privilege-escalation-vulnerability-2025-2/

Match rules

CPE URI Source package Min version Max version
guix >= 0 < 1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
guix edge-community 1.4.0-r7 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
guix edge-community 1.4.0-r8 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
guix 3.22-community 1.4.0-r7 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable