Privilege escalation has been fixed in the GNU Guix package manager. For Debian 11 bullseye, this problem has been fixed in version 1.2.0-4+deb11u3. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3959-1
It was discovered that the daemon of the GNU Guix functional package manager was susceptible to privilege escalation. For additional information please refer to https://guix.gnu.org/en/blog/2024/build-user-takeover-vulnerability/ . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5805-1
It was discovered that insufficient restriction of unix daemon sockets in the GNU Guix functional package manager could result in sandbox bypass. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5669-1
Get the latest Linux and open source security news straight to your inbox.