CVE-2023-29402

Public on 2023-06-08
Modified on 2024-03-29
Description
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not affected (modules retrieved using GOPATH-mode, i.e. GO111MODULE=off, may be affected).
Severity
Important severity
Important
CVSS v3 Base Score
8.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 golang 2023-07-13 ALAS-2023-1784 Fixed
Amazon Linux 2 - Core golang 2023-07-17 ALAS2-2023-2131 Fixed
Amazon Linux 2 - Golang1.19 Extra golang 2023-08-07 ALAS2GOLANG1.19-2023-001 Fixed
Amazon Linux 2023 golang 2023-07-19 ALAS2023-2023-269 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
NVD CVSSv3 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H