¡¾Â©¶´Í¨¸æ¡¿Go Darwin ¹¹½¨´úÂëÖ´ÐЩ¶´(CVE-2025-22867)
Ðû²¼Ê±¼ä 2025-02-07Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Go Darwin ¹¹½¨´úÂëÖ´ÐЩ¶´ | ||
CVE ID | CVE-2025-22867 | ||
©¶´ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖʱ¼ä | 2025-02-07 |
©¶´ÆÀ·Ö | 7.5 | ©¶´Æ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Go£¨Ò²³ÆΪ Golang£©ÊÇÓÉ Google ¿ª·¢µÄ¿ªÔ´±à³ÌÓïÑÔ£¬Ö¼ÔÚÌṩ¸ßЧ¡¢¼ò½àºÍÒ×ÓÚ²¢·¢±à³ÌµÄ¹¦Ð§¡£Ëü¾ßÓÐÀ¬»ø»ØÊÕ¡¢ÄÚ´æÄþ¾²ºÍÇ¿´óµÄ²¢·¢Ö§³Ö£¨goroutines£©¡£Go ÓïÑԹ㷺ӦÓÃÓÚ·þÎñÆ÷¶Ë¿ª·¢¡¢ÍøÂç±à³ÌºÍÔƼÆËãµÈÁìÓò£¬ÌرðÊʺÏÐèÒª¸ßÐÔÄܺͿÉÀ©Õ¹ÐÔµÄÓ¦Óá£
2025Äê2ÔÂ7ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½GoÓïÑÔ¹Ù·½Ðû²¼Á˹ØÓÚCVE-2025-22867©¶´µÄͨ¸æ¡£¸Ã©¶´Ó°ÏìGo 1.24rc2°æ±¾µÄ©¶´£¬´æÔÚÓÚDarwin£¨macOS£©Æ½Ì¨ÉÏ¡£¸Ã©¶´Ô´ÓÚGo¹¹½¨¹ý³ÌÖУ¬CGOÄ£¿éÓëApple°æ±¾µÄld£¨Á´½ÓÆ÷£©ÅäºÏʹÓÃʱ£¬ÀÄÓÃ#cgo LDFLAGSÖ¸ÁîÖеÄ@executable_path¡¢@loader_path»ò@rpathµÈÌØÊâ·¾¶Öµ£¬¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£¹¥»÷Õß¿Éͨ¹ý¾«ÐĽṹµÄGoÄ£¿é´¥·¢´Ë©¶´£¬ÔÚ¹¹½¨¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øΣ¼°ÏµÍ³Äþ¾²¡£
¶þ¡¢Ó°Ï췶Χ
Go 1.24rc2
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£º
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£