CVE-2025-59378
published 2025-09-15CVE-2025-59378: In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the…
PriorityP425medium5.7CVSS 3.1
AVLACLPRNUINSCCLILAN
EPSS
0.14%
3.4th percentile
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | guix | — | — |
| gnu | guix | < 1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45 | 1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
osv5.7MEDIUM
vendor_debian5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-59378: guix - In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can ...
vendor_debian·2025·CVSS 5.7
CVE-2025-59378 [MEDIUM] CVE-2025-59378: guix - In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can ...
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
Scope: local
bullseye: open
sid: open
GHSA
GHSA-75hx-v6j6-m6h7: In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to ga
ghsa_unreviewed·2025-09-15
CVE-2025-59378 [MEDIUM] CWE-669 GHSA-75hx-v6j6-m6h7: In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to ga
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
OSV
CVE-2025-59378: In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to ga
osv·2025-09-15·CVSS 5.7
CVE-2025-59378 [MEDIUM] CVE-2025-59378: In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to ga
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-15
Published