Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:5941 https://access.redhat.com/errata/RHSA-2026:5941
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:5943 https://access.redhat.com/errata/RHSA-2026:5943
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:5942 https://access.redhat.com/errata/RHSA-2026:5942
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:5944 https://access.redhat.com/errata/RHSA-2026:5944
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:6949 https://access.redhat.com/errata/RHSA-2026:6949
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:7833 https://access.redhat.com/errata/RHSA-2026:7833
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:7834 https://access.redhat.com/errata/RHSA-2026:7834
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:7878 https://access.redhat.com/errata/RHSA-2026:7878
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:7879 https://access.redhat.com/errata/RHSA-2026:7879
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:7877 https://access.redhat.com/errata/RHSA-2026:7877
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:7876 https://access.redhat.com/errata/RHSA-2026:7876
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:7883 https://access.redhat.com/errata/RHSA-2026:7883