VDB

DEBIAN-CVE-2023-39323

DEBIAN-CVE-2023-39323 PUBLISHED CVSS 8.100000381469727 HIGH

Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11golang-1.151.15.15-1, 1.15.15-1~deb11u1, 1.15.15-1~deb11u2
Debian:12golang-1.191.19.13-1, 1.19.13-1~bpo11+1, 1.19.13-1~bpo12+1

Timeline

  • Oct 5, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›