Protection mechanism failure in Go programming language - CVE-2025-61731

 

Protection mechanism failure in Go programming language - CVE-2025-61731

Published: March 16, 2026


Vulnerability identifier: #VU124035
CSH Severity: High
CVSS v4 BT: 4.8 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2025-61731
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due CgoPkgConfig allows execution of pkg-config binary with flags that are not explicitly safe-listed. A remote attacker can trick the victim into executing arbitrary commands on the system.


Affected software

Go programming language
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-help
golang-devel
golang
golang (Red Hat package)
go-toolset
golang-bin
golang-src
golang-misc
golang-docs
golang-shared
golang-tests
delve
golang-race
Splunk Enterprise

How to mitigate CVE-2025-61731

Install updates from vendor's website.

Go programming language - addressed in versions 1.24.12, 1.25.6
Splunk Enterprise - addressed in versions 9.3.12, 9.4.11, 10.0.6, 10.2.3
golang-help - addressed in versions 1.15.7-59, 1.17.3-47, 1.21.4-42, 1.21.4-43, 1.21.4-45
golang-devel - addressed in versions 1.15.7-59, 1.17.3-47, 1.21.4-42, 1.21.4-43, 1.21.4-45
golang - addressed in versions 1.15.7-59, 1.17.3-47, 1.21.4-42, 1.21.4-43, 1.21.4-45
golang (Red Hat package) - addressed in versions 1.17.13-11.el9_0, 1.19.13-24.el9_2, 1.25.8-1.el9_6, 1.25.8-1.el9_7, 1.25.8-1.el10_0, 1.25.8-1.el10_1
go-toolset - addressed in versions 1.24.6-1, 1.25.8-1.0.1
golang-bin - addressed in versions 1.24.11-2, 1.25.8-1.0.1
golang-src - addressed in versions 1.24.11-2, 1.25.8-1.0.1
golang-misc - addressed in versions 1.24.11-2, 1.25.8-1.0.1
golang-docs - addressed in versions 1.24.11-2, 1.25.8-1.0.1
golang - addressed in versions 1.24.11-2, 1.25.8-1.0.1
golang-shared - update to 1.24.11-2
golang-tests - addressed in versions 1.24.11-2, 1.25.8-1.0.1
delve - update to 1.25.2-1.0.2
golang-race - update to 1.25.8-1.0.1

External References

Related Security Bulletins