CVE-2023-39323
Published: 5 October 2023
Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.
Priority
Status
Package | Release | Status |
---|---|---|
golang-1.19 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(end of standard support)
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
trusty |
Ignored
(end of standard support)
|
|
upstream |
Needs triage
|
|
xenial |
Ignored
(end of standard support)
|
|
golang-1.20 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(end of standard support)
|
focal |
Released
(1.20.3-1ubuntu0.1~20.04.1)
|
|
jammy |
Released
(1.20.3-1ubuntu0.1~22.04.1)
|
|
lunar |
Released
(1.20.3-1ubuntu0.2)
|
|
mantic |
Released
(1.20.8-1ubuntu0.23.10.1)
|
|
noble |
Does not exist
|
|
trusty |
Ignored
(end of standard support)
|
|
upstream |
Released
(1.20.9-1)
|
|
xenial |
Ignored
(end of standard support)
|
|
golang-1.21 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(end of standard support)
|
focal |
Released
(1.21.1-1~ubuntu20.04.2)
|
|
jammy |
Released
(1.21.1-1~ubuntu22.04.2)
|
|
lunar |
Released
(1.21.1-1~ubuntu23.04.2)
|
|
mantic |
Released
(1.21.1-1ubuntu0.23.10.1)
|
|
noble |
Not vulnerable
(1.21.5-1)
|
|
trusty |
Ignored
(end of standard support)
|
|
upstream |
Released
(1.21.2-1)
|
|
xenial |
Ignored
(end of standard support)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.1 |
Attack vector | Network |
Attack complexity | High |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
- https://go.dev/issue/63211
- https://go.dev/cl/533215
- https://groups.google.com/g/golang-announce/c/XBa1oHDevAo
- https://pkg.go.dev/vuln/GO-2023-2095
- https://github.com/golang/go/commit/2ddfc04d12da7028334ab4f8effbc3a78b92d9d2 (go1.21.2)
- https://github.com/golang/go/commit/31d5b604ac0adb58aec4870ac1b974c08312fd49 (go1.20.9)
- https://ubuntu.com/security/notices/USN-6574-1
- https://www.cve.org/CVERecord?id=CVE-2023-39323
- NVD
- Launchpad
- Debian