已开启
fix(cve): 修复 CVE-2026-27140 在 golang 中的漏洞 #629
fix(cve): 修复 CVE-2026-27140 在 golang 中的漏洞 #629
已开启
HouRunZe创建于 4月21日
共 2 个文件变更+54-1
@@ -0,0 +1,49 @@
1+From 299cde89960ef6612800ab8f71f568cb10d6f6d9 Mon Sep 17 00:00:00 2001
2+From: Neal Patel <nealpatel@google.com>
3+Date: Tue, 24 Feb 2026 23:05:34 +0000
4+Subject: [PATCH] [release-branch.go1.25] cmd/go: disallow cgo trust boundary
5+ bypass
6+MIME-Version: 1.0
7+Content-Type: text/plain; charset=UTF-8
8+Content-Transfer-Encoding: 8bit
9+ 
10+The cgo compiler implicitly trusts generated files
11+with 'cgo' prefixes; thus, SWIG files containing 'cgo'
12+in their names will cause bypass of the trust boundary,
13+leading to code smuggling or arbitrary code execution.
14+ 
15+The cgo compiler will now produce an error if it
16+encounters any SWIG files containing this prefix.
17+ 
18+Thanks to Juho Forsén of Mattermost for reporting this issue.
19+ 
20+Fixes #78335
21+Fixes CVE-2026-27140
22+ 
23+Change-Id: I44185a84e07739b3b347efdb86be7d8fa560b030
24+Reviewed-on: https://go-internal-review.googlesource.com/c/go/+/3520
25+Reviewed-by: Nicholas Husin <husin@google.com>
26+Reviewed-by: Damien Neil <dneil@google.com>
27+Reviewed-on: https://go-internal-review.googlesource.com/c/go/+/3989
28+---
29+ src/cmd/go/internal/work/exec.go | 4 ++++
30+ 1 file changed, 4 insertions(+)
31+ 
32+diff --git a/src/cmd/go/internal/work/exec.go b/src/cmd/go/internal/work/exec.go
33+index 6bfc83aae2..8c3bac51e6 100644
34+--- a/src/cmd/go/internal/work/exec.go
35++++ b/src/cmd/go/internal/work/exec.go
36+@@ -3231,6 +3231,10 @@ func (b *Builder) swigIntSize(objdir string) (intsize string, err error) {
37+
38+ // Run SWIG on one SWIG input file.
39+ func (b *Builder) swigOne(a *Action, file, objdir string, pcCFLAGS []string, cxx bool, intgosize string) (outGo, outC string, err error) {
40++ if strings.HasPrefix(file, "cgo") {
41++ return "", "", errors.New("SWIG file must not use prefix 'cgo'")
42++ }
43++
44+ p := a.Package
45+ sh := b.Shell(a)
46+
47+--
48+2.43.0
49+ 
@@ -66,7 +66,7 @@
66 66 
67Name: golang67Name: golang
68Version: 1.24.268Version: 1.24.2
69-Release: 4569+Release: 46
70Summary: The Go Programming Language70Summary: The Go Programming Language
71License: BSD and Public Domain71License: BSD and Public Domain
72URL: https://golang.org/72URL: https://golang.org/
@@ -156,6 +156,7 @@ Patch1028: 1028-CVE-2025-61726-net-url-add-urlmaxqueryparams-GODEBUG.patch
156Patch1029: 1029-CVE-2026-27139-os-avoid-escape-from-Root-via-ReadDir.patch156Patch1029: 1029-CVE-2026-27139-os-avoid-escape-from-Root-via-ReadDir.patch
157Patch1030: 1030-CVE-2026-27142-html-template-properly-escape-URLs-in-meta.patch157Patch1030: 1030-CVE-2026-27142-html-template-properly-escape-URLs-in-meta.patch
158Patch1031: 1031-CVE-2026-25679-net-url-reject-IPv6-literal-not-at.patch158Patch1031: 1031-CVE-2026-25679-net-url-reject-IPv6-literal-not-at.patch
159+Patch1032: 1032-CVE-2026-27140-cmd-go-disallow-cgo-trust-boundary-bypass.patch
159 160 
160# Backport of RVA23161# Backport of RVA23
161Patch2001: 2001-cpu-internal-provide-runtime-detection-of-RISC-V-ext.patch162Patch2001: 2001-cpu-internal-provide-runtime-detection-of-RISC-V-ext.patch
@@ -436,6 +437,9 @@ fi
436%files devel -f go-tests.list -f go-misc.list -f go-src.list437%files devel -f go-tests.list -f go-misc.list -f go-src.list
437 438 
438%changelog439%changelog
440+* Tue Apr 21 2026 HouRunZe <1043170898@qq.com> - 1.24.2-46
441+- fix CVE-2026-27140: cmd/go: disallow cgo trust boundary bypass
442+ 
439* Sat Mar 21 2026 huzhangying <huzhangying@huawei.com> - 1.24.2-45443* Sat Mar 21 2026 huzhangying <huzhangying@huawei.com> - 1.24.2-45
440- Type:CVE-2026-27139,CVE-2026-27142,CVE-2026-25679444- Type:CVE-2026-27139,CVE-2026-27142,CVE-2026-25679
441- SUG:NA445- SUG:NA