INTEL_REPORT
LWN.net (kernel & development security) · published 7/3/2026, 3:54:01 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Four vulnerabilities in Guix The GNU Guix project has announced three vulnerabilities in the guix substitute utility as well as a fourth that affects the guix pull and guix time-machine commands. The impact of the vulnerabilities ranges from remote privilege escalation to local disclosure of sensitive files. The remote exploitation of guix substitute only requires that the vulnerable system attempt to download a binary substitute. Any configured substitute server, including …
https://lwn.net/Articles/1081199
sha256:f8cf5cf67674ccffbf615b828f8537229ab07b692365d0e08137faff53567681
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.