Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:22668

Опубликовано: 04 дек. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: go-toolset:rhel8 security update

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

  • os/exec: Unexpected paths returned from LookPath in os/exec (CVE-2025-47906)

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
delvex86_641.module+el8.10.0+40035+ee0a7047delve-1.25.2-1.module+el8.10.0+40035+ee0a7047.x86_64.rpm
golangx86_642.module+el8.10.0+40037+cec252d2golang-1.25.3-2.module+el8.10.0+40037+cec252d2.x86_64.rpm
golang-binx86_642.module+el8.10.0+40037+cec252d2golang-bin-1.25.3-2.module+el8.10.0+40037+cec252d2.x86_64.rpm
golang-docsnoarch2.module+el8.10.0+40037+cec252d2golang-docs-1.25.3-2.module+el8.10.0+40037+cec252d2.noarch.rpm
golang-miscnoarch2.module+el8.10.0+40037+cec252d2golang-misc-1.25.3-2.module+el8.10.0+40037+cec252d2.noarch.rpm
golang-racex86_642.module+el8.10.0+40037+cec252d2golang-race-1.25.3-2.module+el8.10.0+40037+cec252d2.x86_64.rpm
golang-srcnoarch2.module+el8.10.0+40037+cec252d2golang-src-1.25.3-2.module+el8.10.0+40037+cec252d2.noarch.rpm
golang-testsnoarch2.module+el8.10.0+40037+cec252d2golang-tests-1.25.3-2.module+el8.10.0+40037+cec252d2.noarch.rpm
go-toolsetx86_642.module+el8.10.0+40037+cec252d2go-toolset-1.25.3-2.module+el8.10.0+40037+cec252d2.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
10 месяцев назад

ELSA-2025-22668: go-toolset:ol8 security update (MODERATE)

CVSS3: 6.5
ubuntu
около 1 года назад

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

CVSS3: 6.5
redhat
около 1 года назад

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

CVSS3: 6.5
nvd
около 1 года назад

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

CVSS3: 8.8
msrc
около 1 года назад

Unexpected paths returned from LookPath in os/exec