Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29155 | In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended). |
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu guix |
|
| Vendors & Products |
Gnu
Gnu guix |
Mon, 15 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-669 | |
| Metrics |
cvssV3_1
|
Mon, 15 Sep 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-15T20:23:44.642Z
Reserved: 2025-09-15T00:00:00.000Z
Link: CVE-2025-59378
Updated: 2025-09-15T20:23:40.627Z
Status : Deferred
Published: 2025-09-15T06:15:37.917
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-59378
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:52:31Z
EUVD