#1150350 guix: security issues with substitutes (2026-07)

Package:
guix
Source:
guix
Description:
GNU Guix functional package manager
Submitter:
Vagrant Cascadian
Date:
2026-10-08 21:35:03 UTC
Severity:
normal
Tags:
#1150350#5
Date:
2026-10-08 20:59:03 UTC
From:
To:
Several security issues were discovered in Guix:

https://guix.gnu.org/en/blog/2026/guix-substitute-pull-vulnerabilities/

  "Several security issues (CVE IDs pending) have been identified in
   guix substitute, a helper utility invoked by guix-daemon, which
   enable a variety of harmful activities including remote privilege
   escalation to the build daemon user, remote store corruption, and
   potentially local disclosure of sensitive files accessible to the
   build daemon user."

There is some existing work to mitigate this by backporting upstream
patches:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1148812&pow_referer=#10

  "I managed to backport patches on top of Guix 1.5.0.

   They are in the guix-1.5.0-backports branch in
https://git.sr.ht/~gnutoo/guix."

But I have been unable to successfully use guix substitutes with those
patches applied. Will try to get more details on that at some point.


live well,
  vagrant