Article 6RMDW A vulnerability in the Guix build system

A vulnerability in the Guix build system

by
daroc
from LWN.net on (#6RMDW)

The Guix project hasdisclosed a security vulnerability in the build daemon that the distribution uses to build and install software locally. The vulnerability allows an existing unprivileged user to get access to a setuid binary, and from there potentially interfere with any other software built or installed on the computer. The project recommends upgrading the guix daemon now, to avoid the issue.

This exploit requires the ability to start a derivation build and theability to run arbitrary code with access to the store in the root PIDnamespace on the machine the build occurs on. As such, this representsan increased risk primarily to multi-user systems and systems usingdedicated privilege-separation users for various daemons: withoutspecial sandboxing measures, any process of theirs can take advantageof this vulnerability.
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments