CVE-2017-1000455: GNU Guixsd
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.
Affected products
- GNU Guixsd: up to and including 0.13.0
Published 2018-01-02. Last modified 2026-06-17.