VDB

DEBIAN-CVE-2023-29402

DEBIAN-CVE-2023-29402 PUBLISHED CVSS 9.800000190734863 CRITICAL

The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not affected (modules retrieved using GOPATH-mode, i.e. GO111MODULE=off, may be affected).

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:12golang-1.190, 1.19.10-1, 1.19.10-2
Debian:11golang-1.151.15.15-1~deb11u1, 1.15.15-1~deb11u2, 1.15.15-1~deb11u3

Exploit Intelligence

Timeline

  • Jun 8, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›