logo

GNU Guix Vulnerabilities Let Attackers Overwrite Arbitrary Files and Escalate Privileges

ID: 91e2a7d3-7741-57a8-9103-67b312d10490

STIX ID: report--91e2a7d3-7741-57a8-9103-67b312d10490

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-10

Date Updated: 2026-07-21

Author: Divya

...
...

A security researcher disclosed multiple serious vulnerabilities in GNU Guix's substitute handling that allow attacker-controlled substitutes or network impersonation to write arbitrary files as the guix-daemon user (potentially affecting root-owned locations like /etc/passwd), return mismatched metadata to force package substitution, and expose sensitive data via file:// URIs and malformed narinfo responses; fixes were released and administrators are advised to upgrade to a specified commit or disable substitutes and restart the guix-daemon as interim mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.