Name
CVE-2023-39323
Description
Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://go.dev/issue/63211Issue Tracking
https://pkg.go.dev/vuln/GO-2023-2095Vendor Advisory
https://security.gentoo.org/glsa/202311-09Third Party Advisory
https://security.netapp.com/advisory/ntap-20231020-0001/Third Party Advisory
https://go.dev/issue/63211Issue Tracking
https://pkg.go.dev/vuln/GO-2023-2095Vendor Advisory
https://security.gentoo.org/glsa/202311-09Third Party Advisory
https://security.netapp.com/advisory/ntap-20231020-0001/Third Party Advisory
Analysis#
Vulnerability Ratings#
8.1
CVSSv31
8.1
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Not Affected
openwrt
master
1.26.4-r1
Not Affected
openwrt
openwrt-25.12
1.24.13-r1
Not Affected
openwrt
openwrt-25.12
1.26.4-r1
Not Affected
yocto
master
1.26.4
Not Affected
yocto
master
1.26.4
Not Affected
yocto
scarthgap
1.22.12
Not Affected
yocto
scarthgap
1.22.12
Not Affected