CVE-2025-22870

Public on 2025-03-07
Modified on 2025-03-07
Description
NOTE: http://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ
NOTE: http://github.com/golang/go/issues/71984
NOTE: Fixed by: http://github.com/golang/go/commit/334de7982f8ec959c74470dd709ceedfd6dbd50a (go1.24.1)
NOTE: Fixed by: http://github.com/golang/go/commit/25177ecde0922c50753c043579d17828b7ee88e7 (go1.23.7)
Severity
Medium severity
Medium
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 golang No Fix Planned
HAQM Linux 2 - Core golang 2025-03-13 ALAS2-2025-2795 Fixed
HAQM Linux 2023 golang 2025-03-26 ALAS2023-2025-913 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
NVD CVSSv3 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L