Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-61732

Опубликовано: 05 фев. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 3openshift-golang-builder-containerAffected
Red Hat Enterprise Linux 9go-toolsetAffected
Red Hat OpenShift Virtualization 4openshift-golang-builder-containerAffected
Red Hat Enterprise Linux 10golangFixedRHSA-2026:270616.02.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgolangFixedRHSA-2026:319224.02.2026
Red Hat Enterprise Linux 8go-toolsetFixedRHSA-2026:270816.02.2026
Red Hat Enterprise Linux 8.2 Advanced Update Supportgo-toolsetFixedRHSA-2026:346802.03.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportgo-toolsetFixedRHSA-2026:347002.03.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Ongo-toolsetFixedRHSA-2026:347002.03.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportgo-toolsetFixedRHSA-2026:348902.03.2026

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2437016cmd/cgo: Potential code smuggling via doc comments in cmd/cgo

EPSS

Процентиль: 0%
0.00006
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 2 месяцев назад

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

CVSS3: 8.6
nvd
около 2 месяцев назад

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

CVSS3: 8.6
debian
около 2 месяцев назад

A discrepancy between how Go and C/C++ comments were parsed allowed fo ...

CVSS3: 8.6
github
около 2 месяцев назад

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

CVSS3: 8.6
fstec
около 2 месяцев назад

Уязвимость компонента cmd/cgo языка программирования Go, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 0%
0.00006
Низкий

7.4 High

CVSS3