CVE-2024-24787: Go Toolchain Cmd/go

Medium severity, CVSS 6.4. EPSS: 0.8% chance of exploitation in the next 30 days.

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

Affected products

  • Go Toolchain Cmd/go: before 1.21.10 (fixed in 1.21.10); from 1.22.0-0, before 1.22.3 (fixed in 1.22.3)
  • Golang Go: version 1.21.0 only; version 1.22 only

Published 2024-05-08. Last modified 2026-06-17.