Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27143

Опубликовано: 08 апр. 2026
Источник: debian

Описание

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.26fixed1.26.2-1package
golang-1.25fixed1.25.9-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19not-affectedpackage
golang-1.15not-affectedpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU

  • https://github.com/golang/go/issues/78333

  • Fixed by: https://github.com/golang/go/commit/c4b4bd7b3aefeb67a541912df0733bde68333bfc (go1.26.2)

  • Fixed by: https://github.com/golang/go/commit/7d2dd3488cdfbddda14c18c455d3263df75a46fc (go1.25.9)

  • Introduced by: https://github.com/golang/go/commit/bb5ff5342d31723ecf245e8e53b79bce23b88839 (go1.21rc1)

  • https://ciolek.dev/posts/when-the-compiler-lies

Связанные уязвимости

CVSS3: 9.8
ubuntu
6 месяцев назад

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

CVSS3: 8.1
redhat
6 месяцев назад

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

CVSS3: 9.8
nvd
6 месяцев назад

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

msrc
6 месяцев назад

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

CVSS3: 9.8
redos
5 месяцев назад

Уязвимость golang