Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-13941

Опубликовано: 18 авг. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-13941: golang security update (IMPORTANT)

[1.24.6-1]

  • Update to Go 1.24.6 (fips-1)
  • Resolves: RHEL-106464

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

go-toolset

1.24.6-1.el10_0

golang

1.24.6-1.el10_0

golang-bin

1.24.6-1.el10_0

golang-docs

1.24.6-1.el10_0

golang-misc

1.24.6-1.el10_0

golang-race

1.24.6-1.el10_0

golang-src

1.24.6-1.el10_0

golang-tests

1.24.6-1.el10_0

Oracle Linux x86_64

go-toolset

1.24.6-1.el10_0

golang

1.24.6-1.el10_0

golang-bin

1.24.6-1.el10_0

golang-docs

1.24.6-1.el10_0

golang-misc

1.24.6-1.el10_0

golang-race

1.24.6-1.el10_0

golang-src

1.24.6-1.el10_0

golang-tests

1.24.6-1.el10_0

Связанные CVE

Связанные уязвимости

CVSS3: 8.6
ubuntu
3 месяца назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
redhat
3 месяца назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
nvd
3 месяца назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
msrc
2 месяца назад

Unexpected command execution in untrusted VCS repositories in cmd/go

CVSS3: 8.6
debian
3 месяца назад

The go command may execute unexpected commands when operating in untru ...