Back to Database
Status published
Medium
CVE-2025-59378
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file...
Vulnerability Description
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59378
Credits & Attribution
No credits recorded in the NVD database.
References
More from GNU
View All →CVE-2025-8746
GNU libopts __strstr_sse2 memory corruption
Medium
4.8
CVE-2025-8736
GNU cflow Lexer c.c yylex buffer overflow
Medium
4.8
CVE-2025-8735
GNU cflow Lexer c.c yylex null pointer dereference
Medium
4.8
CVE-2025-8225
GNU Binutils DWARF Section dwarf.c process_debug_info memory leak
Medium
4.8
CVE-2025-8224
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
Medium
4.8
Affected Vendor
Affected Software
Guix
Vulnerable Versions:
0
Timeline
Official Publish:
September 15th, 2025
Last Modified:
September 15th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.