#1115303 guix: CVE-2025-59378

Package:
src:guix
Source:
src:guix
Submitter:
Salvatore Bonaccorso
Date:
2026-10-07 22:25:06 UTC
Severity:
normal
Tags:
#1115303#5
Date:
2025-09-15 12:10:28 UTC
From:
To:
Hi,

The following vulnerability was published for guix.

CVE-2025-59378[0]:
| In guix-daemon in GNU Guix before 1618ca7, a content-addressed-
| mirrors file can be written to create a setuid program that allows a
| regular user to gain the privileges of the build user that runs it
| (even after the build has ended).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-59378
https://www.cve.org/CVERecord?id=CVE-2025-59378
[1] https://codeberg.org/guix/guix/pulls/2419
[2] https://guix.gnu.org/en/blog/2025/privilege-escalation-vulnerability-2025-2/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1115303#10
Date:
2026-10-06 20:43:09 UTC
From:
To:
Hello,

Bug #1115303 in guix reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/guix/-/commit/1348890c1e01d4917e96022fdcb58ea5137e4a1c
------------------------------------------------------------------------
debian/changelog: Mark CVEs fixed in 1.5.0. (Closes: #1108318, #1115303)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1115303

#1115303#17
Date:
2026-10-07 22:24:42 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
guix, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1115303@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Vagrant Cascadian <vagrant@debian.org> (supplier of updated guix package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 07 Oct 2026 13:03:54 -0700
Source: guix
Architecture: source
Version: 1.5.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Scheme Team <debian-scheme@lists.debian.org>
Changed-By: Vagrant Cascadian <vagrant@debian.org>
Closes: 1096790 1108318 1115303
Changes:
 guix (1.5.0-1) unstable; urgency=medium
 .
   * New upstream release.
     (Closes: #1108318, #1115303, #1096790)
     Fixes: CVE-2025-46415, CVE-2025-46416, CVE-2025-52991, CVE-2025-52992,
     CVE-2025-52993, CVE-2025-59378
   * debian/patches: Move all test related patches to a subdir.
   * debian/control: Update Build-Depends on guile-git to 0.10.0.
   * debian/upstream/signing-key.asc: Add key for Rutherther.
   * debian/patches: Disable tests accessing network or other mysterious failures.
   * debian/patches: Disable more tests.
   * debian/patches: tests/toml.scm: Disable expected failures that passed.
   * debian/watch: Update to format version 5.
   * debian/control: Remove "Priority" field.
   * debian/control: Remove "Rules-Requires-Root" field.
   * debian/control: Update Standards-Version to 4.7.3.
   * debian/control: Update Maintainer to Debian Scheme Team.
   * debian/patches: Fixes to apparmor profiles from upstream.
   * Add Build-Depends on dh-apparmor and call from debian/rules.
   * debian/sysusers.d/guix-daemon.conf: Add "guix-daemon" user, drop
     _guixbuild group and _guixbuilder users.
   * debian/patches: Drop --build-users-group from guix-daemon.service.
   * debian/patches: Refresh use-c-utf8-locale.
   * debian/guix.postinst: Ensure guix-daemon user owns /gnu/store, /var/guix
     and /var/log/guix.
   * debian/control: Add uidmap to Recommends.
   * debian/control: Add slirp4netns to Build-Depends and Recommends.
   * debian/control: Update to Standards-Version 4.7.4.
   * debian/copyright: Update for 1.5.0
Checksums-Sha1:
 8bcaaf4365442af2a90733347092c00318b8b01c 1964 guix_1.5.0-1.dsc
 6fbceccf056d2ee86ce43fd3ba0ef2fada5be5e4 87422418 guix_1.5.0.orig.tar.gz
 e37d23f3bf36083b6c4eff0637b1ef64bc4f22c6 833 guix_1.5.0.orig.tar.gz.asc
 43509e2c9bc166a4a7780f08f3d2b82c7500c03f 74312 guix_1.5.0-1.debian.tar.xz
 cda78301609b1d27fcabc0a5775f19e56f631657 10673 guix_1.5.0-1_amd64.buildinfo
Checksums-Sha256:
 057867b5d8335a53403f07a220737a2a17c06a70da3eb907f4f978e16b6a7af7 1964 guix_1.5.0-1.dsc
 df2102eed00aff0b17275654a42f094c8a1117ec065884eb1ff76005e47415c5 87422418 guix_1.5.0.orig.tar.gz
 4632c379832f2f55dbc02e4b8504f3564d374af08220c6e8bdcf505702e2c7ce 833 guix_1.5.0.orig.tar.gz.asc
 8383eab56717abed832e0bfefd952bf3d727ed07c404352e872dcfa0212b5f31 74312 guix_1.5.0-1.debian.tar.xz
 f2295c494a79348030c084e75999dd019ab120c9db5d719315470e49021d4fa8 10673 guix_1.5.0-1_amd64.buildinfo
Files:
 f60117b7924ef528ecd7679d9976aba7 1964 admin optional guix_1.5.0-1.dsc
 48aa9b7223bc2e6b3e8b6f53121ea932 87422418 admin optional guix_1.5.0.orig.tar.gz
 96f3dd7c223599c7914d5998af65cf8a 833 admin optional guix_1.5.0.orig.tar.gz.asc
 ebd0f5571e6cc3d63e28d2f0152a391f 74312 admin optional guix_1.5.0-1.debian.tar.xz
 79311b504505413c185f0996b72fcec0 10673 admin optional guix_1.5.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iIkEARYKADEWIQRlgHNhO/zFx+LkXUXcUY/If5cWqgUCasbCJRMcdmFncmFudEBk
ZWJpYW4ub3JnAAoJENxRj8h/lxaq0tMA/Rw5kBSSgiO01KLm8kgH41QwzhHN1wme
CbzVgsiaIbjsAP4oBNIN9Tg9PfgkwhRKtt89TF+eIXS0qkZU4NDLSojZAg==
=G8Zb
-----END PGP SIGNATURE-----