Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27140

Опубликовано: 08 апр. 2026
Источник: debian

Описание

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.26fixed1.26.2-1package
golang-1.25fixed1.25.9-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU

  • https://github.com/golang/go/issues/78335

  • Fixed by: https://github.com/golang/go/commit/096f21b1c50fe62bc54c1fb1ede60fca63239123 (go1.26.2)

  • Fixed by: https://github.com/golang/go/commit/abaa0cbb259e059ee60c33a7507eddc1fe7d20fa (go1.25.9)

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

CVSS3: 9
redhat
4 месяца назад

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

CVSS3: 8.8
nvd
4 месяца назад

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

msrc
4 месяца назад

Code execution vulnerability in SWIG code generation in cmd/go

CVSS3: 8.8
github
4 месяца назад

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.