¡¾·ì϶¹«¸æ¡¿Go Darwin ¹¹½¨´úÂëÖ´Ðзì϶(CVE-2025-22867)
°ä²¼¹¦·ò 2025-02-07Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Go Darwin ¹¹½¨´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-22867 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-02-07 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Go£¨Ò²³ÆÎª Golang£©ÊÇÓÉ Google ¿ª·¢µÄ¿ªÔ´±à³Ì˵»°£¬Ö¼ÔÚÌṩ¸ßЧ¡¢¼ò½àºÍÒ×ÓÚ²¢·¢±à³ÌµÄÖ°ÄÜ¡£ËüÓµÓÐÀ¬»ø»ØÊÕ¡¢Äڴ氲ȫºÍ׳´óµÄ²¢·¢Ö§³Ö£¨goroutines£©¡£Go ˵»°¿í·ºÀûÓÃÓÚ·þÎñÆ÷¶Ë¿ª·¢¡¢ÍøÂç±à³ÌºÍÔÆÍÆËãµÈÁìÓò£¬³ö¸ñÊʺϱØÒª¸ß»úÄܺͿÉÀ©´óÐÔµÄÀûÓá£
2025Äê2ÔÂ7ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Go˵»°¹Ù·½°ä²¼Á˹ØÓÚCVE-2025-22867·ì϶µÄ²¼¸æ¡£¸Ã·ì϶ӰÏìGo 1.24rc2°æ±¾µÄ·ì϶£¬´æÔÚÓÚDarwin£¨macOS£©Æ½Ì¨ÉÏ¡£¸Ã·ì϶ԴÓÚGo¹¹½¨¹ý³ÌÖУ¬CGOÄ£¿éÓëApple°æ±¾µÄld£¨Á´½ÓÆ÷£©¹²Í¬Ê¹ÓÃʱ£¬ÀÄÓÃ#cgo LDFLAGSÖ¸ÁîÖеÄ@executable_path¡¢@loader_path»ò@rpathµÈÌØÊâõè¾¶Öµ£¬¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£¹¥»÷Õß¿Éͨ¹ý¾«ÐÄ»ú¹ØµÄGoÄ£¿é´¥·¢´Ë·ì϶£¬ÔÚ¹¹½¨¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øÎ£¼°ÏµÍ³°²È«¡£
¶þ¡¢Ó°ÏìÁìÓò
Go 1.24rc2
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


¾©¹«Íø°²±¸11010802024551ºÅ