In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
{ "binaries": [ { "binary_name": "guix", "binary_version": "1.3.0-4ubuntu0.1~esm1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-59378.json"
{ "binaries": [ { "binary_name": "guix", "binary_version": "1.4.0-6ubuntu0.1~esm1" } ] }