CVE-2024-24787
Moderate
CVE-2024-24787
Exploit probability
0.8%
Published
June 6, 2024
Required by
Not available
Last source change
January 28, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2024-2825
View original source
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.
Open Source Vulnerabilities
BIT-golang-2024-24787
View original source
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.
Open Source Vulnerabilities
CGA-67wh-9fxr-2w4p
View original source
05 / REFERENCES
Further evidence
- https://go.dev/cl/583815
- https://go.dev/issue/67119
- https://groups.google.com/g/golang-announce/c/wkkO4P9stm0
- http://www.openwall.com/lists/oss-security/2024/05/08/3
- https://nvd.nist.gov/vuln/detail/CVE-2024-24787
- https://pkg.go.dev/vuln/GO-2024-2825
- https://security.netapp.com/advisory/ntap-20240531-0006/