CVE-2025-32438
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 378
CWE ID 379
Summary
CVE-2025-32438 is a local privilege escalation vulnerability affecting all users of make-initrd-ng in NixOS. This tool, used for copying binaries and their dependencies, allows a local user to craft a program that will be executed by root during system shutdown, if systemd.shutdownRamfs.enable is enabled (the default setting). This vulnerability can lead to significant security risks. Users can mitigate this issue by disabling systemd.shutdownRamfs.enable or applying the available patches for NixOS 24.11, 25.05, and the unstable branch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Nixpkgs
Affected Vendors
- NixOS