We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-8244

Walk/WalkDir in path/filepath susceptible to symlink race



Description

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

Reserved 2024-08-27 | Published 2025-08-06 | Updated 2025-08-06 | Assigner Go

Problem types

CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition

Product status

Default status
affected

References

go.dev/issue/70007

pkg.go.dev/vuln/GO-2025-9999

cve.org (CVE-2024-8244)

nvd.nist.gov (CVE-2024-8244)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-8244

Support options

Helpdesk Chat, Email, Knowledgebase