CVE-2025-61731
Go toolchain cmd/go, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support 취약점
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
- 대응 우선순위
- 점검
- CVSS
- 7.8
- EPSS
- 0.53% 백분위 42.0% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.01.29