make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default) a local user is able to create a program that will be executed by root during shutdown. Patches exist for NixOS 24.11 and 25.05 / unstable. As a workaround, set systemd.shutdownRamfs.enable = false;.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled (the default) a local user is able to create a program that will be executed by root during shutdown. Patches exist for NixOS 24.11 and 25.05 / unstable. As a workaround, set systemd.shutdownRamfs.enable = false;. | |
Title | Local privilege escalation in make-initrd-ng | |
Weaknesses | CWE-378 CWE-379 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-15T20:08:58.816Z
Reserved: 2025-04-08T10:54:58.368Z
Link: CVE-2025-32438

Updated: 2025-04-15T20:08:53.437Z

Status : Awaiting Analysis
Published: 2025-04-15T20:15:39.533
Modified: 2025-04-16T13:25:59.640
Link: CVE-2025-32438

No data.