Bug 2467825 (CVE-2026-39817)

Summary: CVE-2026-39817 cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dymurray, gparvin, jmatthew, rhaigner, rjohnson, whayutin
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the "go tool pack" subcommand, a component of the Go programming language tools. This vulnerability allows an attacker to craft a malicious archive file. When this archive is extracted using the "pack" subcommand, it can lead to arbitrary file writes on the filesystem, potentially allowing an attacker to create or modify files in unintended locations.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-07 20:02:06 UTC
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

Comment 1 errata-xmlrpc 2026-06-01 00:43:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:22120 https://access.redhat.com/errata/RHSA-2026:22120

Comment 2 errata-xmlrpc 2026-06-01 01:00:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:22121 https://access.redhat.com/errata/RHSA-2026:22121

Comment 3 errata-xmlrpc 2026-06-01 01:04:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:22112 https://access.redhat.com/errata/RHSA-2026:22112

Comment 4 errata-xmlrpc 2026-08-03 15:59:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:49702 https://access.redhat.com/errata/RHSA-2026:49702

Comment 5 errata-xmlrpc 2026-08-03 17:34:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:49712 https://access.redhat.com/errata/RHSA-2026:49712

Comment 6 errata-xmlrpc 2026-08-20 18:47:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:57649 https://access.redhat.com/errata/RHSA-2026:57649