Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22867

Опубликовано: 06 фев. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.

A vulnerability was found in the cmd/go golang package. On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive.

Отчет

This issue only affects go1.24rc2. The go1.24rc2 version is not used in any of the Red Hat products, therefore, Red Hat is not affected by this vulnerability.

Меры по смягчению последствий

No mitigation is available for this issue other than updating the affected package to the version containing the fix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10golangNot affected
Red Hat Enterprise Linux 8golangNot affected
Red Hat Enterprise Linux 8go-toolset:rhel8/golangNot affected
Red Hat Enterprise Linux 9golangNot affected
Red Hat Enterprise Linux 9rhel9/go-toolsetNot affected
Red Hat Enterprise Linux 9ubi9/go-toolsetNot affected
Red Hat Storage 3golangNot affected
Red Hat Trusted Artifact Signerrhtas/fulcio-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2344234cmd/go: Arbitrary code execution during build on darwin in cmd/go

EPSS

Процентиль: 65%
0.00485
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.

CVSS3: 7.5
debian
11 месяцев назад

On Darwin, building a Go module which contains CGO can trigger arbitra ...

CVSS3: 7.5
github
11 месяцев назад

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.

suse-cvrf
11 месяцев назад

Security update for go1.24

suse-cvrf
11 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 65%
0.00485
Низкий

7.5 High

CVSS3