Logo
vulnerabilityCVE-2024-8244
Name
CVE-2024-8244
Source
NVD ( link)Debian ( link)
Description
The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.
CWEs
-
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Vulnerability Ratings#


3.7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Exploitable
openwrt
master
1.27.0-r1
Exploitable
openwrt
openwrt-25.12
1.24.13-r1
Exploitable
openwrt
openwrt-25.12
1.26.6-r1
Exploitable
yocto
master
1.26.6
Exploitable
yocto
master
1.26.6
Exploitable
yocto
scarthgap
1.22.12
Exploitable
yocto
scarthgap
1.22.12
Exploitable