INFSA-2025:13940: go-toolset:rhel8 security update
Information about definition
Identificator: INFSA-2025:13940
Type: security
Release date: 2025-08-27 16:16:58 UTC
Information about package
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Vulnerabilities description
- CVE-2025-4674
A flaw was found in cmd/go. The go command can execute arbitrary commands when processing untrusted version control system (VCS) repositories containing malicious configuration. This issue occurs because the command interprets VCS metadata, potentially leading to unintended command execution. This vulnerability allows a malicious actor to trigger this by providing a repository with a crafted VCS configuration, resulting in arbitrary code execution within the context of the go process.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2025-4674
|
no information | 8.6 | no information |
Updated packages