Gnu Guix vulnerabilities
5 known vulnerabilities affecting gnu/guix.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-52867P3HIGHCVSS 8.1≥ 0, < 1.2.0-4+deb11u32024-11-17
CVE-2024-52867 [HIGH] CVE-2024-52867: guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (
guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, and restart a
osv
CVE-2019-18192P3HIGHCVSS 7.8v1.0.12019-10-17
CVE-2019-18192 [HIGH] CVE-2019-18192: GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent d
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
nvd
CVE-2024-27297P4MEDIUMCVSS 5.9≥ 0, < 1.2.0-4+deb11u22024-03-11
CVE-2024-27297 [MEDIUM] CVE-2024-27297: Nix is a package manager for Linux and other Unix systems
Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors to files in the Nix store to another program running on the host (or another fixed-output derivation) via Unix domain sockets in the abstract namespace. This allows to modify the output of the derivation, after Nix has registered the path as "valid" and immutable in the Nix databa
osv
CVE-2021-27851P4MEDIUMCVSS 5.5≥ 0.11.0, < 1.2.02021-04-26
CVE-2021-27851 [MEDIUM] CWE-264 CVE-2021-27851: A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix build`, that makes its build directory world-writable. The user then creates a hardli
nvdosv
CVE-2025-59378P4MEDIUMCVSS 5.7fixed in 1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe452025-09-15
CVE-2025-59378 [MEDIUM] CWE-669 CVE-2025-59378: In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
nvd