Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27143

Опубликовано: 08 апр. 2026
Источник: debian
EPSS Низкий

Описание

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.26fixed1.26.2-1package
golang-1.25fixed1.25.9-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU

  • https://github.com/golang/go/issues/78333

  • Fixed by: https://github.com/golang/go/commit/c4b4bd7b3aefeb67a541912df0733bde68333bfc (go1.26.2)

  • Fixed by: https://github.com/golang/go/commit/7d2dd3488cdfbddda14c18c455d3263df75a46fc (go1.25.9)

  • https://ciolek.dev/posts/when-the-compiler-lies

EPSS

Процентиль: 41%
0.00536
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

CVSS3: 8.1
redhat
3 месяца назад

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

CVSS3: 9.8
nvd
3 месяца назад

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

msrc
3 месяца назад

Missing bound checks can lead to memory corruption in safe Go in cmd/compile

CVSS3: 9.8
github
3 месяца назад

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.

EPSS

Процентиль: 41%
0.00536
Низкий