CVE-2025-59378 Details
Description
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
A privilege escalation vulnerability has been identified in the guix-daemon component of GNU Guix, affecting versions prior to commit 1618ca7. This vulnerability allows a regular user to gain the privileges of the build user that executes a specially crafted setuid program, created using a content-addressed-mirrors file. The issue persists even after the build process has concluded. In systems with a rootless guix-daemon, this also grants the user the privileges of the guix-daemon itself.
Users are advised to upgrade the guix-daemon to commit 1618ca7 or any later version. Instructions for upgrading are available in the GNU Guix manual.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2025CISA-ADP
Assessed Sep 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://codeberg.org/guix/guix/commit/1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45 | [email protected] | Source CodeVendor |
| https://guix.gnu.org/en/blog/2025/privilege-escalation-vulnerability-2025-2/ | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-669 | Incorrect Resource Transfer Between Spheres | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GNU Guix | < 1618ca7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2025 | New CVE Received | [email protected] |
Volerion