Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Caleb Ristvedt

#20548of 56,330
13.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-37452
5.7
2025-01-01
Gnu Guix · Gnu Guix · CVE-2025-59378
**Name of the Vulnerable Software and Affected Versions** GNU Guix versions prior to 1618ca7 **Description** A content-addressed-mirrors file can be written to create a setuid program. This allows a regular user to gain the privileges of the build user, even after the build process has completed. **Recommendations** Update to a version prior to 1618ca7.
PT-2024-35469
8.1
2024-11-08
Gnu Guix · Gnu Guix · CVE-2024-52867
**Name of the Vulnerable Software and Affected Versions** GNU Guix versions before 5ab3c4c **Description** A privilege escalation issue exists because build outputs are accessible by local users before file metadata concerns, such as for setuid and setgid programs, are properly addressed. This issue can be remediated within the product via certain pull, reconfigure, and restart actions. Both 5ab3c4c and 5582241 are needed to resolve the issue. **Recommendations** For GNU Guix versions before 5ab3c4c, perform the following actions to resolve the issue: Pull the necessary updates. Reconfigure the system. Restart the guix-daemon service. Ensure that both 5ab3c4c and 5582241 are applied to fully resolve the issue.