Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07952

Опубликовано: 15 апр. 2026
Источник: fstec
CVSS3: 5.9
CVSS2: 4.6
EPSS Низкий

Описание

Уязвимость команды go tool pack языка программирования Go связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю получить доступ на чтение и запись произвольных файлов

Вендор

ООО «Ред Софт»
The Go Project

Наименование ПО

РЕД ОС
Go

Версия ПО

8.0 (РЕД ОС)
до 1.25.10 (Go)
от 1.26.0 до 1.26.3 (Go)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,6)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,9)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://groups.google.com/g/golang-announce/c/qcCIEXso47M
https://go-review.googlesource.com/c/go/+/767520
https://pkg.go.dev/vuln/GO-2026-4979
https://github.com/MaxMood96/go/commit/7409ada33f99c0d74db2b0389c51a15de116e48d
https://github.com/golang/go/issues/78790
https://github.com/golang/go/issues/78791
https://go.googlesource.com/go/+/7409ada33f99c0d74db2b0389c51a15de116e48d
Для Ред ОС:
http://repo.red-soft.ru/redos/8.0/x86_64/updates/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 7%
0.0017
Низкий

5.9 Medium

CVSS3

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
redos
около 1 месяца назад

Уязвимость golang

CVSS3: 5.9
ubuntu
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

CVSS3: 5.9
redhat
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

CVSS3: 5.9
nvd
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

msrc
3 месяца назад

Invoking "go tool pack" does not sanitize output paths in cmd/go

EPSS

Процентиль: 7%
0.0017
Низкий

5.9 Medium

CVSS3

4.6 Medium

CVSS2