• CVE-2025-47906

发布时间: 2025年9月5日

修改时间: 2025年9月12日

概要

A vulnerability was found in Google Go up to 1.23.11/1.24.5 (Programming Language Software). It has been declared as problematic.The manipulation of the argument PATH with an unknown input leads to a unknown weakness.As an impact it is known to affect integrity.Upgrading to version 1.23.12 or 1.24.6 eliminates this vulnerability.

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Local
CVSS评分 N/A 4.0
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity None
User Interaction None
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2867 golang security update 2025年9月12日
KylinSec-SA-2025-2901 golang security update 2025年9月28日

影响产品

产品 状态
KY3.4-5A golang Fixed
V6 golang Fixed
KY3.5.3 golang Fixed
KY3.5.2 golang Fixed