On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.
History

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Golang
Golang go
CPEs cpe:2.3:a:golang:go:1.21.0:-:*:*:*:*:*:*
Vendors & Products Golang
Golang go
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2025-02-13T17:40:26.439Z

Reserved: 2024-01-30T16:05:14.758Z

Link: CVE-2024-24787

cve-icon Vulnrichment

Updated: 2024-08-01T23:28:12.679Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-08T16:15:08.183

Modified: 2024-11-21T08:59:42.297

Link: CVE-2024-24787

cve-icon Redhat

No data.