摘要:
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.
安全等级: Low
公告ID: KylinSec-SA-2025-1124
发布日期: 2025年2月17日
关联CVE: CVE-2025-22867
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2025-22867 | KY3.4-5A | golang | Unaffected |
CVE-2025-22867 | V6 | golang | Unaffected |