• A vulnerability in the Guix build system

    From LWN.net@1337:1/100 to All on Monday, October 21, 2024 14:45:05
    A vulnerability in the Guix build system

    Date:
    Mon, 21 Oct 2024 13:40:34 +0000

    Description:
    The Guix project has disclosed a security vulnerability in the build daemon that the distribution uses to build and install software locally. The vulnerability allows an existing unprivileged user to get access to a setuid binary, and from there potentially interfere with any other software built or installed on the computer. The project recommends upgrading the guix daemon now, to avoid the issue. This exploit requires the ability to start a derivation build and the
    ability to run arbitrary code with access to the store in the root PID namespace on the machine the build occurs on. As such, this represents
    an increased risk primarily to multi-user systems and systems using
    dedicated privilege-separation users for various daemons: without
    special sandboxing measures, any process of theirs can take advantage
    of this vulnerability.

    ======================================================================
    Link to news story:
    https://lwn.net/Articles/994865/


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)