golang-1.25.8-1.el9_7
エラータID: AXSA:2026-370:03
The golang packages provide the Go programming language compiler.
Security Fix(es):
* cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive (CVE-2025-61731)
* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2025-61731
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
Update packages.
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
N/A
SRPMS
- golang-1.25.8-1.el9_7.src.rpm
MD5: b24f7b390730a1f75b2bde50992a5231
SHA-256: 9250a63c9077f0427a29a37b5828560e04648b2f44434fb408960ec0b3744a0d
Size: 32.76 MB
Asianux Server 9 for x86_64
- golang-1.25.8-1.el9_7.x86_64.rpm
MD5: 3380143d83247a544e94a15f14054f5d
SHA-256: d602160314e0cc4e985b947a58f30708a31c5c8b275211b19ee715fa43e6b6ed
Size: 1.25 MB - golang-bin-1.25.8-1.el9_7.x86_64.rpm
MD5: 5328ea65c7ab2a9070a87e3138f3126c
SHA-256: fd4ffa0ec0d0fe693456d5cbf3ad6696698bd656b8e1aa704f9c56b63efdd86f
Size: 36.49 MB - golang-docs-1.25.8-1.el9_7.noarch.rpm
MD5: c33fdb6736941ed993d135e30ddeb96b
SHA-256: f083356d74ffa972c13de77147eeab91e19ab39dea2d3f123d37a7392e0d3ea3
Size: 108.80 kB - golang-misc-1.25.8-1.el9_7.noarch.rpm
MD5: 81828a35ef3ff0f53189544ceacb0e2b
SHA-256: c8222bc25237ab9de406f6db2f1fa96649fed9ff5a32b43f6d3bb2405d1d91f8
Size: 41.69 kB - golang-race-1.25.8-1.el9_7.x86_64.rpm
MD5: adeb95ac39d154457c3b6f3306c48b97
SHA-256: 5ec59ef8574fbfba255887e7f447ff716de2d0752632dee09af58603bfa517d5
Size: 1.68 MB - golang-src-1.25.8-1.el9_7.noarch.rpm
MD5: b9df8b80ead47444a5ac0aa1d623caef
SHA-256: 7ed80b297df9ec6b5d448723428a4d9f87474c9c4325acae081a9d05d4c967b5
Size: 11.43 MB - golang-tests-1.25.8-1.el9_7.noarch.rpm
MD5: 8c7ea4c208d0cd144903ed638b2c94de
SHA-256: 33042c0f2870909678a37fd58d01684de20053ea83993f1868a5bd518a70d370
Size: 11.48 MB - go-toolset-1.25.8-1.el9_7.x86_64.rpm
MD5: a284d6c70806abd4b22a11bf0355287d
SHA-256: d7b23218846da6ca71cd12018889c93ad53c23a0e62db1c80103d652db7f77d0
Size: 9.63 kB