GNU Guix Vulnerabilities Let Attackers Overwrite Arbitrary Files and Escalate Privileges
ID: 91e2a7d3-7741-57a8-9103-67b312d10490
STIX ID: report--91e2a7d3-7741-57a8-9103-67b312d10490
Feed Name: GBHackers
A security researcher disclosed multiple serious vulnerabilities in GNU Guix's substitute handling that allow attacker-controlled substitutes or network impersonation to write arbitrary files as the guix-daemon user (potentially affecting root-owned locations like /etc/passwd), return mismatched metadata to force package substitution, and expose sensitive data via file:// URIs and malformed narinfo responses; fixes were released and administrators are advised to upgrade to a specified commit or disable substitutes and restart the guix-daemon as interim mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
