Vulnerability Description
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://codeberg.org/guix/guix/commit/1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45
- https://guix.gnu.org/en/blog/2025/privilege-escalation-vulnerability-2025-2/
FAQ
What is CVE-2025-59378?
CVE-2025-59378 is a vulnerability with a CVSS score of 5.7 (MEDIUM). In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (...
How severe is CVE-2025-59378?
CVE-2025-59378 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59378?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.