REDHAT-BUG-2467825: Medium severity go go tool pack vulnerability
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2467825?
The severity of REDHAT-BUG-2467825 is classified as medium with a score of 4.
How do I fix REDHAT-BUG-2467825?
To fix REDHAT-BUG-2467825, ensure that you validate and sanitize input filenames before using the 'go tool pack' command.
What are the potential risks of REDHAT-BUG-2467825?
The potential risks of REDHAT-BUG-2467825 include the possibility of malicious archives writing files to arbitrary locations on the filesystem.
Which software is affected by REDHAT-BUG-2467825?
The software affected by REDHAT-BUG-2467825 is the 'go tool pack' subcommand from the Go programming language.
When was REDHAT-BUG-2467825 published?
REDHAT-BUG-2467825 was published on May 7, 2026.