Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-39817

Опубликовано: 07 мая 2026
Источник: debian
EPSS Низкий

Описание

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.25fixed1.25.10-1package
golang-1.26fixed1.26.3-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://go-review.googlesource.com/c/go/+/767520

  • https://github.com/golang/go/issues/78778

  • https://groups.google.com/g/golang-announce/c/qcCIEXso47M

EPSS

Процентиль: 7%
0.0017
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

CVSS3: 5.9
redhat
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

CVSS3: 5.9
nvd
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

msrc
3 месяца назад

Invoking "go tool pack" does not sanitize output paths in cmd/go

CVSS3: 5.9
github
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

EPSS

Процентиль: 7%
0.0017
Низкий