Race condition in Go programming language - CVE-2025-47907

 

Race condition in Go programming language - CVE-2025-47907

Published: August 14, 2025 / Updated: January 19, 2026


Vulnerability identifier: #VU114080
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47907
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to tamper with the application. 

The vulnerability exists due to a race condition when canceling a DB query. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system. A remote user can overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.


Affected software

Go programming language
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Development Tools Module
openSUSE Leap
openEuler
Netezza Appliance
Financial Transaction Manager for RedHat OpenShift
Robotic Process Automation for Cloud Pak
Dell EMC OpenManage Enterprise Modular
IBM Observability with Instana
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IT Service Intelligence (ITSI)
iDRAC10
Red Hat OpenShift AI (RHOAI)
Cryostat
App Connect Enterprise Certified Container
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
skopeo-debugsource
skopeo-debuginfo
containers-common
skopeo
skopeo-tests
golang-devel
golang
golang-help
golang (Red Hat package)
go1.23-openssl-doc
go1.23-openssl-race
go1.23-openssl
go1.23-openssl-debuginfo
go1.23-doc
go1.23
go1.23-race
go1.24-openssl
go1.24-openssl-race
go1.24-openssl-doc
go1.24
go1.24-race
go1.24-doc
go1.24-openssl-debuginfo
go1.25-openssl-debuginfo
go1.25-openssl-race
go1.25-openssl-doc
go1.25-openssl
go1.25-race
go1.25
go1.25-doc
podman (Red Hat package)
Splunk Enterprise

How to mitigate CVE-2025-47907

Install updates from vendor's website.

Go programming language - addressed in versions 1.23.12, 1.24.6
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Observability with Instana - update to 1.0.304
Multicluster Engine for Kubernetes - addressed in versions 2.8.4, 2.10.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.5
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.7.9, 4.8.6
IT Service Intelligence (ITSI) - update to 4.21.2
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.5, 30.0.1
skopeo-debugsource - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
skopeo-debuginfo - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
containers-common - update to 1.1.0-13
skopeo - addressed in versions 1.1.0-13, 1.8.0-7, 1.14.2-6
skopeo-tests - update to 1.14.2-6
golang-devel - addressed in versions 1.15.7-53, 1.17.3-41, 1.21.4-35, 1.21.4-36
golang - addressed in versions 1.15.7-53, 1.17.3-41, 1.21.4-35, 1.21.4-36
golang-help - addressed in versions 1.15.7-53, 1.17.3-41, 1.21.4-35, 1.21.4-36
golang (Red Hat package) - addressed in versions 1.17.13-7.el9_0, 1.19.13-19.el9_2, 1.21.13-11.el9_4
go1.23-openssl-doc - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-openssl-race - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-openssl - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-openssl-debuginfo - addressed in versions 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1
go1.23-doc - update to 1.23.12-150000.1.40.1
go1.23 - update to 1.23.12-150000.1.40.1
go1.23-race - update to 1.23.12-150000.1.40.1
go1.24-openssl - addressed in versions 1.24.6-150000.1.12.1, 1.24.6-150600.13.9.1
go1.24-openssl-race - addressed in versions 1.24.6-150000.1.12.1, 1.24.6-150600.13.9.1
go1.24-openssl-doc - addressed in versions 1.24.6-150000.1.12.1, 1.24.6-150600.13.9.1
go1.24 - update to 1.24.6-150000.1.32.1
go1.24-race - update to 1.24.6-150000.1.32.1
go1.24-doc - update to 1.24.6-150000.1.32.1
go1.24-openssl-debuginfo - update to 1.24.6-150600.13.9.1
go1.25-openssl-debuginfo - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-openssl-race - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-openssl-doc - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-openssl - addressed in versions 1.25.0-150000.1.3.1, 1.25.0-150600.13.3.1, 1.25.6-150000.1.9.1, 1.25.6-150600.13.9.1
go1.25-race - addressed in versions 1.25.0-150000.1.5.1, 1.25.3-150000.1.19.1
go1.25 - addressed in versions 1.25.0-150000.1.5.1, 1.25.3-150000.1.19.1
go1.25-doc - addressed in versions 1.25.0-150000.1.5.1, 1.25.3-150000.1.19.1
iDRAC10 - addressed in versions 1.30.10.50, 1.30.10.51
Dell EMC OpenManage Enterprise Modular - update to 2.20.20
Red Hat OpenShift AI (RHOAI) - update to 2.22.3
Cryostat - update to 4.1.0
podman (Red Hat package) - addressed in versions 4.9.4-18.el9_4.4, 5.6.0-6.el9_7
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.18, 4.18.25
App Connect Enterprise Certified Container - update to 12.16.0

External References

Related Security Bulletins