CVE-2024-24787: Go Toolchain Cmd/go
Medium severity, CVSS 6.4. EPSS: 0.8% chance of exploitation in the next 30 days.
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.
Affected products
- Go Toolchain Cmd/go: before 1.21.10 (fixed in 1.21.10); from 1.22.0-0, before 1.22.3 (fixed in 1.22.3)
- Golang Go: version 1.21.0 only; version 1.22 only
Published 2024-05-08. Last modified 2026-06-17.