CVE-2023-29405
The go command may execute arbitrary code at build time when using cgo.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. Flags containing embedded spaces are mishandled, allowing disallowed flags to be smuggled through the LDFLAGS sanitization by including them in the argument of another flag. This only affects usage of the gccgo compiler.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- golang/go · fedoraproject/fedora
- Source
- security@golang.org
References
- https://go.dev/cl/501224Patch
- https://go.dev/issue/60306Issue Tracking
- https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZ2O6YCO2IZMZJELQGZYR2WAUNEDLYV6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBS3IIK6ADV24C5ULQU55QLT2UE762ZX/Mailing List
- https://pkg.go.dev/vuln/GO-2023-1842Vendor Advisory
- https://security.gentoo.org/glsa/202311-09
- https://go.dev/cl/501224Patch
- https://go.dev/issue/60306Issue Tracking
- https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZ2O6YCO2IZMZJELQGZYR2WAUNEDLYV6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBS3IIK6ADV24C5ULQU55QLT2UE762ZX/Mailing List
- https://pkg.go.dev/vuln/GO-2023-1842Vendor Advisory
- https://security.gentoo.org/glsa/202311-09
- https://security.netapp.com/advisory/ntap-20241206-0003/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.