# Security Advisory

Published articles for Security Advisory.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## 'guix substitute' and 'guix pull' Vulnerabilities

DevFeed: ['guix substitute' and 'guix pull' Vulnerabilities](<https://devfeed.tech/articles/guix-substitute-and-guix-pull-vulnerabilities-34148.md>)

Original publisher: [Read original article](<https://guix.gnu.org/blog/2026/guix-substitute-pull-vulnerabilities//>)

Author: Caleb Ristvedt

Published: 2026-07-02T17:00:00Z

Content type: release

Language: en

Sources: [GNU Guix -- Blog](<https://devfeed.tech/sources/gnu-guix-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [mitm](<https://devfeed.tech/tags/mitm.md>), [root](<https://devfeed.tech/tags/root.md>), [security](<https://devfeed.tech/tags/security.md>), [security-advisory](<https://devfeed.tech/tags/security-advisory.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [user](<https://devfeed.tech/tags/user.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article details several security vulnerabilities in Guix substitute and guix pull, including remote privilege escalation, remote store corruption, possible disclosure of sensitive files, and file overwrite issues. It advises users to upgrade the Guix daemon and describes a regression affecting some unprivileged users.

### Source excerpt

Several security issues (CVE IDs pending) have been identified in guix substitute , a helper utility invoked by guix-daemon , which enable a variety of harmful activities including remote privilege escalation to the build daemon user , remote store corruption , and potentially local disclosure of sensitive files accessible to the build daemon user. All systems are affected, whether or not guix-daemon is running with root privileges; the harm that can be done when guix-daemon runs without root privileges is more limited. You are strongly advised to upgrade your daemon now (see...

## Nix Weekly Recap: 2024-07-07

DevFeed: [Nix Weekly Recap: 2024-07-07](<https://devfeed.tech/articles/nix-weekly-recap-2024-07-07-34725.md>)

Original publisher: [Read original article](<https://nixpkgs.news/archive/2024-07-07/>)

Published: 2024-07-07T00:00:00Z

Content type: news

Language: en

Sources: [nixpkgs.news](<https://devfeed.tech/sources/nixpkgs-news.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Development](<https://devfeed.tech/topics/development.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [FIRST](<https://devfeed.tech/topics/first.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [github](<https://devfeed.tech/tags/github.md>), [modular](<https://devfeed.tech/tags/modular.md>), [module](<https://devfeed.tech/tags/module.md>), [news](<https://devfeed.tech/tags/news.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [recap](<https://devfeed.tech/tags/recap.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [security-advisory](<https://devfeed.tech/tags/security-advisory.md>), [weekly](<https://devfeed.tech/tags/weekly.md>)

### AI overview

This weekly Nix ecosystem recap announces that nixpkgs.news will stop issuing new releases and focus primarily on news about Lix and Aux. It also covers an OpenSSH CVE-2024-6387 security advisory, the modular make-shell project, the faster nix-search utility, and updates to Nixpkgs governance.

### Source excerpt

Critical SSH vulnerability, improved DX for dev shells, faster search, and Nix Constitutional Assembly updates.

## High ROI Security Advisory Boards

DevFeed: [High ROI Security Advisory Boards](<https://devfeed.tech/articles/high-roi-security-advisory-boards-36826.md>)

Original publisher: [Read original article](<https://shostack.org/blog/high-roi-security-advisory-boards/>)

Author: Adam

Published: 2018-12-21T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [security](<https://devfeed.tech/tags/security.md>), [security-advisory](<https://devfeed.tech/tags/security-advisory.md>)

### AI overview

The article discusses the value of Security Advisory Boards and argues that achieving high value requires sustained effort from both company staff and board members.

### Source excerpt

Discussing the value of Security Advisory Boards