A vulnerability in Guix's privileged daemon shows how package restoration, when mishandled, can cross from software delivery into root-level file tampering.
Multiple critical flaws in Guix’s substitute and channel-update workflows highlight how a package manager built for integrity can still be shaken by unsafe parsing, archive handling, and privileged daemon logic.