HomeDefault status
unaffected
Any version before 1.24.13
affected
1.25.0-0 (semver) before 1.25.7
affected
Description
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
Problem types
CWE-94: Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 1.24.13
1.25.0-0 (semver) before 1.25.7
Credits
RyotaK (https://ryotak.net) of GMO Flatt Security Inc.
References
groups.google.com/g/golang-announce/c/K09ubi9FQFk