Debian Package Tracker
Register | Log in
Subscribe

guix

GNU Guix functional package manager

Choose email to subscribe with

general
  • source: guix (main)
  • version: 1.5.0-1
  • maintainer: Debian Scheme Team (archive) (DMD)
  • uploaders: Vagrant Cascadian [DMD]
  • arch: amd64 arm64 armhf i386 ppc64el riscv64
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.2.0-4+deb11u2
  • o-o-sec: 1.2.0-4+deb11u3
  • unstable: 1.5.0-1
  • exp: 1.4.0+154928+f1810-1
versioned links
  • 1.2.0-4+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.0-4+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.0-9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.0+154928+f1810-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.5.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • guix (9 bugs: 1, 6, 2, 0)
action needed
5 security issues in bookworm high

There are 5 open security issues in bookworm.

5 important issues:
  • CVE-2025-46415: A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-46416: The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52991: The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52992: The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52993: A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
Created: 2025-06-24 Last update: 2025-09-06 12:03
5 security issues in trixie high

There are 5 open security issues in trixie.

5 important issues:
  • CVE-2025-46415: A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-46416: The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52991: The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52992: The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52993: A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
Created: 2025-06-24 Last update: 2025-08-25 17:32
5 security issues in forky high

There are 5 open security issues in forky.

5 important issues:
  • CVE-2025-46415: A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-46416: The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52991: The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52992: The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
  • CVE-2025-52993: A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
Created: 2025-08-09 Last update: 2025-08-10 06:32
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-10-09 03:00
lintian reports 39 warnings normal
Lintian reports 39 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-10-08 Last update: 2026-10-08 18:01
2 open merge requests in Salsa normal
There are 2 open merge requests for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-09-30 Last update: 2026-09-30 03:30
debian/patches: 69 patches to forward upstream low

Among the 71 debian patches available in version 1.5.0-1 of the package, we noticed the following issues:

  • 69 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-10-08 11:00
testing migrations
  • excuses:
    • Migration status for guix (- to 1.5.0-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Updating guix would introduce bugs in testing: #1112143, #1150350
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for diffoscope/332: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, ppc64el: Test triggered
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/g/guix.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-10-07] Accepted guix 1.5.0-1 (source) into unstable (Vagrant Cascadian)
  • [2025-08-26] guix REMOVED from testing (Debian testing watch)
  • [2025-04-27] guix 1.4.0-9 MIGRATED to testing (Debian testing watch)
  • [2025-04-16] Accepted guix 1.4.0-9 (source) into unstable (Vagrant Cascadian)
  • [2025-02-28] Accepted guix 1.4.0+154928+f1810-1 (source) into experimental (Vagrant Cascadian)
  • [2025-02-22] Accepted guix 1.4.0+154710+ab1b5-2 (source) into experimental (Vagrant Cascadian)
  • [2025-02-21] Accepted guix 1.4.0+154710+ab1b5-1 (source) into experimental (Vagrant Cascadian)
  • [2025-02-21] Accepted guix 1.4.0+154709.ab1b557d8f3-1 (source) into experimental (Vagrant Cascadian)
  • [2024-11-22] guix 1.4.0-8 MIGRATED to testing (Debian testing watch)
  • [2024-11-18] Accepted guix 1.2.0-4+deb11u3 (source) into oldstable-security (Adrian Bunk)
  • [2024-11-11] Accepted guix 1.4.0-3+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-11-08] Accepted guix 1.4.0-3+deb12u2 (source) into stable-security (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-10-30] Accepted guix 1.4.0-8 (source) into unstable (Vagrant Cascadian)
  • [2024-08-20] Accepted guix 1.4.0-7 (source) into unstable (Vagrant Cascadian)
  • [2024-06-18] guix REMOVED from testing (Debian testing watch)
  • [2024-06-18] guix REMOVED from testing (Debian testing watch)
  • [2024-04-22] Accepted guix 1.2.0-4+deb11u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-04-22] Accepted guix 1.4.0-3+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-04-22] Accepted guix 1.4.0-3+deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-04-22] Accepted guix 1.2.0-4+deb11u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • [2024-03-29] guix 1.4.0-6 MIGRATED to testing (Debian testing watch)
  • [2024-03-16] Accepted guix 1.4.0-6 (source) into unstable (Vagrant Cascadian)
  • [2023-07-23] guix 1.4.0-5 MIGRATED to testing (Debian testing watch)
  • [2023-07-17] Accepted guix 1.4.0-5 (source) into unstable (Vagrant Cascadian)
  • [2023-06-13] guix 1.4.0-4 MIGRATED to testing (Debian testing watch)
  • [2023-06-04] Accepted guix 1.4.0-4 (source) into unstable (Vagrant Cascadian)
  • [2023-05-02] guix 1.4.0-3 MIGRATED to testing (Debian testing watch)
  • [2023-04-22] Accepted guix 1.4.0-3 (source) into unstable (Vagrant Cascadian)
  • [2023-04-21] Accepted guix 1.4.0-2 (source) into unstable (Vagrant Cascadian)
  • [2023-04-16] Accepted guix 1.2.0-4+deb11u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Vagrant Cascadian)
  • 1
  • 2
bugs [bug history graph]
  • all: 12
  • RC: 3
  • I&N: 7
  • M&W: 2
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 39)
  • buildd: logs, exp, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 83)
  • debian patches

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing