ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 13 sources: “Ubuntu patch wave, 2026-09-10 to 2026-09-16: nine USNs fix 11 CVEs as 24.04.5 point release refreshes install media” — merged summary and timeline →

USN-8773-1: GNU Guix vulnerability

lowAdvisoryimportance 20
AI summary · glm-5.3-flash

Ubuntu issued USN-8773-1 fixing a GNU Guix flaw that exposed build outputs to local users before metadata finalization, enabling possible privilege escalation.

Ubuntu published security notice USN-8773-1 to address a flaw in GNU Guix where build outputs were made accessible to local users before their file metadata was finalized. A local attacker could possibly leverage this window to gain elevated privileges on the affected system. The notice ships updated packages for supported Ubuntu releases and reports no exploitation.

  • GNU Guix exposed build outputs to local users before file metadata was finalized
  • Issue could allow local attackers to gain elevated privileges
  • Ubuntu released patched Guix packages under USN-8773-1
  • No in-the-wild exploitation reported in the notice
Full article

It was discovered that GNU Guix incorrectly made build outputs accessible to local users before their file metadata was finalized. A local attacker could possibly use this issue to gain elevated privileges.

This source does not provide full text. Read it at ubuntu.com.