HomeDefault status
unaffected
Any version before 1.25.9
affected
1.26.0-0 (semver) before 1.26.2
affected
Description
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
Problem types
CWE-190: Integer Overflow or Wraparound
Product status
Any version before 1.25.9
1.26.0-0 (semver) before 1.26.2
Credits
Jakub Ciolek - https://ciolek.dev/
References
groups.google.com/g/golang-announce/c/0uYbvbPZRWU