If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
This is fixed in Go versions 1.25.0: https://github.com/golang/go/commit/ebee011a54f9310099d02a7e7731330539db16cf ... and 1.24.6: https://github.com/golang/go/commit/0f5133b742bf61cda6c98b4cd1d313a330f13f32
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:21856 https://access.redhat.com/errata/RHSA-2025:21856
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:22004 https://access.redhat.com/errata/RHSA-2025:22004
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:22005 https://access.redhat.com/errata/RHSA-2025:22005
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:22181 https://access.redhat.com/errata/RHSA-2025:22181