Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3035 | On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2. |
Fri, 07 Feb 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 06 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 06 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2. | |
| Title | Arbitrary code execution during build on darwin in cmd/go | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-02-06T21:23:25.105Z
Reserved: 2025-01-08T19:11:42.834Z
Link: CVE-2025-22867
Updated: 2025-02-06T20:06:42.113Z
Status : Deferred
Published: 2025-02-06T18:15:32.543
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-22867
OpenCVE Enrichment
No data.
EUVD