CVE-2025-61731
Go toolchain cmd/go, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
- CVSS
- 7.8
- EPSS
- 0.53% 42.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.29