Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.RC
  • Bug#1108318: guix: CVE-2025-46415 CVE-2025-46416 CVE-2025-52991 CVE-202

    From Salvatore Bonaccorso@21:1/5 to All on Wed Jun 25 23:00:01 2025
    Source: guix
    Version: 1.4.0-9
    Severity: grave
    Tags: security upstream
    Justification: user security hole
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

    Hi,

    The following vulnerabilities were published for guix.

    CVE-2025-46415[0], CVE-2025-46416[1], CVE-2025-52991[2],
    CVE-2025-52992[3], CVE-2025-52993[4].


    If you fix the vulnerabilities please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-46415
    https://www.cve.org/CVERecord?id=CVE-2025-46415
    [1] https://security-tracker.debian.org/tracker/CVE-2025-46416
    https://www.cve.org/CVERecord?id=CVE-2025-46416
    [2] https://security-tracker.debian.org/tracker/CVE-2025-52991
    https://www.cve.org/CVERecord?id=CVE-2025-52991
    [3] https://security-tracker.debian.org/tracker/CVE-2025-52992
    https://www.cve.org/CVERecord?id=CVE-2025-52992
    [4] https://security-tracker.debian.org/tracker/CVE-2025-52993
    https://www.cve.org/CVERecord?id=CVE-2025-52993
    [5] https://guix.gnu.org/en/blog/2025/privilege-escalation-vulnerabilities-2025/

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Vagrant Cascadian@21:1/5 to Salvatore Bonaccorso on Tue Jul 15 22:40:01 2025
    On 2025-06-25, Salvatore Bonaccorso wrote:
    CVE-2025-46415[0], CVE-2025-46416[1], CVE-2025-52991[2],
    CVE-2025-52992[3], CVE-2025-52993[4].

    The upstream patchset to fix this is comingled with a lot of other
    upstream changes, but there is some work and discussion about
    backporting the needed fixes:

    https://lists.gnu.org/archive/html/guix-devel/2025-07/msg00098.html

    But the comingling with other changes makes this trickier than in the past.


    I've just managed for the first time to get something to compile at all
    with the security fixes applied:

    https://codeberg.org/GNUtoo/guix-security-fixes/commits/branch/guix-1.4.0-2025-security-fixes

    But that also includes all the other unrelated changes, although it
    fails a few new tests now...


    Guix is basically a rolling release model, and up till recently, there
    had been little active development on the affected parts other than
    security fixes, so previous security fixes were a bit more reasonable to
    apply, even across pretty old versions... but here we are right now.

    Curiously, those "unrelated" changes are actually to allow running
    guix-daemon as an unprivledged user, which has obvious security
    benefits! ... Just not appropriate for Debian's typical security update
    model.


    I am not sure about the future of Guix in Debian at this point, but if
    we can actually get a few people working together on backporting the
    security fixes (either officially or unofficially), obviously that will
    help!


    live well,
    vagrant

    -----BEGIN PGP SIGNATURE-----

    iHUEARYKAB0WIQRlgHNhO/zFx+LkXUXcUY/If5cWqgUCaHa31wAKCRDcUY/If5cW qpotAQChQyOjEZt//ufmimpUaqdX/dVdsWSzWBCsChrUx5iYWgEA+ZL9K8/zcEYv KbkUwX7VvhhTIBKFDSkYXnIZAbwCNQ4=
    =OQqq
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon Jun 8 08:26:26 2026
      from Wales, Uk via Telnet
    • Spearb0y
      Mon Jun 8 06:51:02 2026
      from Massachusetts via SSH
    • Krenn
      Mon Jun 8 05:45:38 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Sun Jun 7 20:58:28 2026
      from Wales, Uk via Telnet
    • Michal Wronka
      Sun Jun 7 19:26:28 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 27:06:46
    Calls: 12,106
    Calls today: 6
    Files: 15,006
    Messages: 6,518,203

© >>> Magnum BBS <<<, 2026