Input validation error in Go programming language - CVE-2025-47906

 

Input validation error in Go programming language - CVE-2025-47906

Published: August 14, 2025


Vulnerability identifier: #VU114079
CSH Severity: Low
CVSS v4 BT: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-47906
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of the PATH environment variable in LookPath. A local user can pass specially crafted strings to the application and execute arbitrary OS commands with elevated privileges. 


Affected software

Go programming language
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Fedora
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
openSUSE Leap
openEuler
Engineering Lifecycle Management
Guardium Data Security Center (GDSC)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-github-facebook-time
complyctl
ibus-bamboo
vhs
gum
docker-buildkit
docker-buildx
alertmanager
kitty
fvwm3
oci-seccomp-bpf-hook
runc
xq
podman-tui
node-exporter
golang-devel
golang
golang-help
gopass-jsonapi
golang (Red Hat package)
prometheus-podman-exporter
skopeo
go1.23-openssl-debuginfo
go1.23-openssl
go1.23-openssl-race
go1.23-openssl-doc
go1.23-race
go1.23-doc
go1.23
golang-src
golang-docs
golang-tests
golang-bin
golang-shared
golang-misc
go-toolset
go1.24-openssl-doc
go1.24-openssl-race
go1.24-openssl
go1.24
go1.24-doc
go1.24-race
go1.24-openssl-debuginfo
go1.25-openssl-race
go1.25-openssl-debuginfo
go1.25-openssl
go1.25-openssl-doc
go1.25-doc
go1.25
go1.25-race
delve
golang-race
cri-o1.31
kubernetes1.31
cri-o1.32
kubernetes1.32
kubernetes1.33
cri-o1.34
kubernetes1.34
containerd
syncthing
vgrep
chezmoi
gh
go-rpm-macros (Red Hat package)
git-lfs
prometheus
gitleaks
staticcheck
Splunk Enterprise
AI Inference Server
App Connect Enterprise Certified Container

How to mitigate CVE-2025-47906

Install updates from vendor's website.

Go programming language - addressed in versions 1.23.12, 1.24.6
Engineering Lifecycle Management - update to 1.3.0
Guardium Data Security Center (GDSC) - update to 3.8.5
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1
golang-github-facebook-time - addressed in versions 0^20251021gite970944-1.el9, 0^20251021gite970944-1.fc41, 0^20251021gite970944-1.fc42
complyctl - addressed in versions 0.1.0-1.fc42, 0.1.0-1.fc43
ibus-bamboo - addressed in versions 0.8.4~RC6-2.fc41, 0.8.4~RC6-2.fc42
vhs - update to 0.9.0-2.fc42
gum - update to 0.16.1-2.fc42
docker-buildkit - addressed in versions 0.25.0-1.fc41, 0.25.0-1.fc42, 0.25.0-1.fc43, 0.25.0-1.fc44
docker-buildx - addressed in versions 0.29.0-1.fc41, 0.29.0-1.fc42, 0.29.0-1.fc43, 0.29.0-1.fc44, 0.29.1-1.fc41, 0.29.1-1.fc42, 0.29.1-1.fc43
alertmanager - addressed in versions 0.31.1-1.el9, 0.31.1-2.fc42
kitty - update to 0.43.0-1.fc42
fvwm3 - addressed in versions 1.1.4-1.fc41, 1.1.4-1.fc42, 1.1.4-1.fc43
oci-seccomp-bpf-hook - addressed in versions 1.2.10-8.fc41, 1.2.10-9.fc42
runc - addressed in versions 1.3.2-1.fc41, 1.3.2-1.fc42, 1.3.2-1.fc43, 1.3.2-1.fc44
xq - addressed in versions 1.4.0-2.el9, 1.4.0-2.el10_1, 1.4.0-2.el10_2, 1.4.0-2.el10_3, 1.4.0-2.fc42
podman-tui - addressed in versions 1.9.0-1.fc41, 1.9.0-1.fc42, 1.9.0-1.fc43
node-exporter - addressed in versions 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42
golang-devel - addressed in versions 1.15.7-53, 1.17.3-41, 1.21.4-35, 1.21.4-36
golang - addressed in versions 1.15.7-53, 1.17.3-41, 1.21.4-35, 1.21.4-36
golang-help - addressed in versions 1.15.7-53, 1.17.3-41, 1.21.4-35, 1.21.4-36
gopass-jsonapi - update to 1.16.0-1.fc43
golang (Red Hat package) - addressed in versions 1.17.13-8.el9_0, 1.19.13-20.el9_2, 1.21.13-12.el9_4
prometheus-podman-exporter - addressed in versions 1.19.0-1.fc41, 1.19.0-1.fc42
skopeo - addressed in versions 1.20.0-3.fc41, 1.20.0-3.fc42
go1.23-openssl-debuginfo - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-openssl - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-openssl-race - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-openssl-doc - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-race - update to 1.23.12-150000.1.40.1
go1.23-doc - update to 1.23.12-150000.1.40.1
go1.23 - update to 1.23.12-150000.1.40.1
golang-src - addressed in versions 1.24.0-9, 1.25.3-2.0.2
golang-docs - addressed in versions 1.24.0-9, 1.25.3-2.0.2
golang-tests - addressed in versions 1.24.0-9, 1.25.3-2.0.2
golang - addressed in versions 1.24.0-9, 1.25.3-2.0.2
golang-bin - addressed in versions 1.24.0-9, 1.25.3-2.0.2
golang-shared - update to 1.24.0-9
golang-misc - addressed in versions 1.24.0-9, 1.25.3-2.0.2
go-toolset - addressed in versions 1.24.6-1, 1.25.3-2.0.2
go1.24-openssl-doc - addressed in versions 1.24.6-150000.1.12.1, 1.24.6-150600.13.9.1
go1.24-openssl-race - addressed in versions 1.24.6-150000.1.12.1, 1.24.6-150600.13.9.1
go1.24-openssl - addressed in versions 1.24.6-150000.1.12.1, 1.24.6-150600.13.9.1
go1.24 - update to 1.24.6-150000.1.32.1
go1.24-doc - update to 1.24.6-150000.1.32.1
go1.24-race - update to 1.24.6-150000.1.32.1
go1.24-openssl-debuginfo - update to 1.24.6-150600.13.9.1
go1.25-openssl-race - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-openssl-debuginfo - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-openssl - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-openssl-doc - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-doc - addressed in versions 1.25.0-150000.1.5.1, 1.25.3-150000.1.19.1
go1.25 - addressed in versions 1.25.0-150000.1.5.1, 1.25.3-150000.1.19.1
go1.25-race - addressed in versions 1.25.0-150000.1.5.1, 1.25.3-150000.1.19.1
delve - update to 1.25.2-1.0.2
golang-race - update to 1.25.3-2.0.2
cri-o1.31 - addressed in versions 1.31.13-1.fc41, 1.31.13-1.fc42, 1.31.13-1.fc43, 1.31.13-1.fc44
kubernetes1.31 - addressed in versions 1.31.14-1.fc41, 1.31.14-1.fc42, 1.31.14-1.fc43, 1.31.14-1.fc44
cri-o1.32 - addressed in versions 1.32.9-1.fc41, 1.32.9-1.fc42, 1.32.9-1.fc43, 1.32.9-1.fc44
kubernetes1.32 - addressed in versions 1.32.10-2.fc41, 1.32.10-2.fc42, 1.32.10-2.fc43, 1.32.10-2.fc44
kubernetes1.33 - addressed in versions 1.33.6-1.fc41, 1.33.6-1.fc42, 1.33.6-1.fc43, 1.33.6-1.fc44
cri-o1.34 - addressed in versions 1.34.1-1.fc41, 1.34.1-1.fc42, 1.34.1-1.fc43, 1.34.1-1.fc44
kubernetes1.34 - addressed in versions 1.34.2-1.fc41, 1.34.2-1.fc42, 1.34.2-1.fc43, 1.34.2-1.fc44
containerd - update to 2.0.7-1.fc42
syncthing - addressed in versions 2.1.1-1.el10_2, 2.1.1-1.el10_3
vgrep - addressed in versions 2.8.0-4.fc41, 2.8.0-4.fc42
chezmoi - addressed in versions 2.69.4-1.el9, 2.69.4-1.el10_2, 2.69.4-1.el10_3, 2.69.4-1.fc42
gh - update to 2.83.0-1.el10_2
go-rpm-macros (Red Hat package) - addressed in versions 3.0.9-12.el9_0, 3.2.0-2.el9_2, 3.2.0-4.el9_4, 3.6.0-11.el9_6, 3.6.0-12.el9_7
AI Inference Server - update to 3.2.5
git-lfs - addressed in versions 3.7.1-1.fc41, 3.7.1-1.fc42
prometheus - update to 3.10.0-1.fc42
gitleaks - update to 8.29.0-1.fc42
App Connect Enterprise Certified Container - update to 12.16.0
staticcheck - update to 2026.1-1.el9

External References

Related Security Bulletins