Privilege Escalation Vulnerability in GNU Guix Daemon
CVE-2025-59378

5.7MEDIUM

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
15 September 2025

What is CVE-2025-59378?

The GNU Guix Daemon contains a vulnerability that permits regular users to create a setuid program through a content-addressed-mirrors file. This flaw allows these users to escalate their privileges to those of the build user operating the daemon, compromising system security even after the build process has completed. The affected versions must be updated to mitigate this risk.

Affected Version(s)

Guix 0 < 1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59378 : Privilege Escalation Vulnerability in GNU Guix Daemon