CVE-2025-52991

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-52991
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-52991.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-52991
Related
Published
2025-06-27T14:15:41Z
Modified
2025-07-01T16:33:20.847600Z
Summary
[none]
Details

The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

References

Affected packages

Debian:11 / guix

Package

Name
guix
Purl
pkg:deb/debian/guix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.0-4
1.2.0-4+deb11u1
1.2.0-4+deb11u2
1.2.0-4+deb11u3
1.3.0~rc1-1
1.3.0-1
1.3.0-2
1.3.0-3
1.3.0-4
1.3.0-5
1.3.0+26720.a2e4e-1
1.3.0+26756.c07b5-1
1.3.0+26756.c07b5-2
1.4.0~rc1-1
1.4.0~rc1-2
1.4.0~rc2-1
1.4.0-1
1.4.0-2
1.4.0-3
1.4.0-4
1.4.0-5
1.4.0-6
1.4.0-7
1.4.0-8
1.4.0-9
1.4.0+154709.ab1b557d8f3-1
1.4.0+154710+ab1b5-1
1.4.0+154710+ab1b5-2
1.4.0+154928+f1810-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / guix

Package

Name
guix
Purl
pkg:deb/debian/guix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.4.0-3
1.4.0-3+deb12u1
1.4.0-3+deb12u2
1.4.0-4
1.4.0-5
1.4.0-6
1.4.0-7
1.4.0-8
1.4.0-9
1.4.0+154709.ab1b557d8f3-1
1.4.0+154710+ab1b5-1
1.4.0+154710+ab1b5-2
1.4.0+154928+f1810-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / guix

Package

Name
guix
Purl
pkg:deb/debian/guix?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.4.0-3
1.4.0-4
1.4.0-5
1.4.0-6
1.4.0-7
1.4.0-8
1.4.0-9
1.4.0+154709.ab1b557d8f3-1
1.4.0+154710+ab1b5-1
1.4.0+154710+ab1b5-2
1.4.0+154928+f1810-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}