CVE-2024-24787 PUBLISHED

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

EPSS 2.71% · 85.8th percentile

Risk Scores

EPSS Score
2.71%
85.8th percentile

Affected Products

VendorProductVersions
Bitnamigolang0, 1.22.0-0
Bitnamigolang0, 1.22.0-0

Timeline

References

Open in Interactive Console →