Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39819

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 4.4

Описание

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

A flaw was found in the 'go bug' command within the Go programming language tools. This command writes to temporary files with predictable names. A local attacker with access to the system's temporary directory could exploit this by creating a symbolic link (symlink) with one of these predictable names. This would cause the 'go bug' command to overwrite the target of the symlink, potentially leading to arbitrary file overwrite.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/addon-manager-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/backplane-rhel9-operatorUnder investigation
Multicluster Engine for Kubernetesmulticluster-engine/clusterlifecycle-state-metrics-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorUnder investigation
Multicluster Engine for Kubernetesmulticluster-engine/maestro-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/managedcluster-import-controller-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/multicloud-manager-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/placement-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/registration-operator-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/work-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2467813cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

CVSS3: 5.3
nvd
3 месяца назад

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

msrc
3 месяца назад

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

CVSS3: 5.3
debian
3 месяца назад

The "go bug" command writes to two files with predictable names in the ...

CVSS3: 5.3
github
3 месяца назад

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

4.4 Medium

CVSS3