已开启
fix(cve): 修复 CVE-2026-27140 在 golang 中的漏洞 #629
HouRunZe创建于 4月21日
fix(cve): 修复 CVE-2026-27140 在 golang 中的漏洞 #629
已开启
共 2 个文件变更+54-1
| @@ -0,0 +1,49 @@ | |||
| 1 | +From 299cde89960ef6612800ab8f71f568cb10d6f6d9 Mon Sep 17 00:00:00 2001 | ||
| 2 | +From: Neal Patel <nealpatel@google.com> | ||
| 3 | +Date: Tue, 24 Feb 2026 23:05:34 +0000 | ||
| 4 | +Subject: [PATCH] [release-branch.go1.25] cmd/go: disallow cgo trust boundary | ||
| 5 | + bypass | ||
| 6 | +MIME-Version: 1.0 | ||
| 7 | +Content-Type: text/plain; charset=UTF-8 | ||
| 8 | +Content-Transfer-Encoding: 8bit | ||
| 9 | + | ||
| 10 | +The cgo compiler implicitly trusts generated files | ||
| 11 | +with 'cgo' prefixes; thus, SWIG files containing 'cgo' | ||
| 12 | +in their names will cause bypass of the trust boundary, | ||
| 13 | +leading to code smuggling or arbitrary code execution. | ||
| 14 | + | ||
| 15 | +The cgo compiler will now produce an error if it | ||
| 16 | +encounters any SWIG files containing this prefix. | ||
| 17 | + | ||
| 18 | +Thanks to Juho Forsén of Mattermost for reporting this issue. | ||
| 19 | + | ||
| 20 | +Fixes #78335 | ||
| 21 | +Fixes CVE-2026-27140 | ||
| 22 | + | ||
| 23 | +Change-Id: I44185a84e07739b3b347efdb86be7d8fa560b030 | ||
| 24 | +Reviewed-on: https://go-internal-review.googlesource.com/c/go/+/3520 | ||
| 25 | +Reviewed-by: Nicholas Husin <husin@google.com> | ||
| 26 | +Reviewed-by: Damien Neil <dneil@google.com> | ||
| 27 | +Reviewed-on: https://go-internal-review.googlesource.com/c/go/+/3989 | ||
| 28 | +--- | ||
| 29 | + src/cmd/go/internal/work/exec.go | 4 ++++ | ||
| 30 | + 1 file changed, 4 insertions(+) | ||
| 31 | + | ||
| 32 | +diff --git a/src/cmd/go/internal/work/exec.go b/src/cmd/go/internal/work/exec.go | ||
| 33 | +index 6bfc83aae2..8c3bac51e6 100644 | ||
| 34 | +--- a/src/cmd/go/internal/work/exec.go | ||
| 35 | ++++ b/src/cmd/go/internal/work/exec.go | ||
| 36 | + func (b *Builder) swigIntSize(objdir string) (intsize string, err error) { | ||
| 37 | + | ||
| 38 | + // Run SWIG on one SWIG input file. | ||
| 39 | + func (b *Builder) swigOne(a *Action, file, objdir string, pcCFLAGS []string, cxx bool, intgosize string) (outGo, outC string, err error) { | ||
| 40 | ++ if strings.HasPrefix(file, "cgo") { | ||
| 41 | ++ return "", "", errors.New("SWIG file must not use prefix 'cgo'") | ||
| 42 | ++ } | ||
| 43 | ++ | ||
| 44 | + p := a.Package | ||
| 45 | + sh := b.Shell(a) | ||
| 46 | + | ||
| 47 | +-- | ||
| 48 | +2.43.0 | ||
| 49 | + | ||
| @@ -66,7 +66,7 @@ | |||
| 66 | 66 | ||
| 67 | Name: golang | 67 | Name: golang |
| 68 | Version: 1.24.2 | 68 | Version: 1.24.2 |
| 69 | -Release: 45 | 69 | +Release: 46 |
| 70 | Summary: The Go Programming Language | 70 | Summary: The Go Programming Language |
| 71 | License: BSD and Public Domain | 71 | License: BSD and Public Domain |
| 72 | URL: https://golang.org/ | 72 | URL: https://golang.org/ |
| @@ -156,6 +156,7 @@ Patch1028: 1028-CVE-2025-61726-net-url-add-urlmaxqueryparams-GODEBUG.patch | |||
| 156 | Patch1029: 1029-CVE-2026-27139-os-avoid-escape-from-Root-via-ReadDir.patch | 156 | Patch1029: 1029-CVE-2026-27139-os-avoid-escape-from-Root-via-ReadDir.patch |
| 157 | Patch1030: 1030-CVE-2026-27142-html-template-properly-escape-URLs-in-meta.patch | 157 | Patch1030: 1030-CVE-2026-27142-html-template-properly-escape-URLs-in-meta.patch |
| 158 | Patch1031: 1031-CVE-2026-25679-net-url-reject-IPv6-literal-not-at.patch | 158 | Patch1031: 1031-CVE-2026-25679-net-url-reject-IPv6-literal-not-at.patch |
| 159 | +Patch1032: 1032-CVE-2026-27140-cmd-go-disallow-cgo-trust-boundary-bypass.patch | ||
| 159 | 160 | ||
| 160 | # Backport of RVA23 | 161 | # Backport of RVA23 |
| 161 | Patch2001: 2001-cpu-internal-provide-runtime-detection-of-RISC-V-ext.patch | 162 | Patch2001: 2001-cpu-internal-provide-runtime-detection-of-RISC-V-ext.patch |
| @@ -436,6 +437,9 @@ fi | |||
| 436 | %files devel -f go-tests.list -f go-misc.list -f go-src.list | 437 | %files devel -f go-tests.list -f go-misc.list -f go-src.list |
| 437 | 438 | ||
| 438 | %changelog | 439 | %changelog |
| 440 | +* Tue Apr 21 2026 HouRunZe <1043170898@qq.com> - 1.24.2-46 | ||
| 441 | +- fix CVE-2026-27140: cmd/go: disallow cgo trust boundary bypass | ||
| 442 | + | ||
| 439 | * Sat Mar 21 2026 huzhangying <huzhangying@huawei.com> - 1.24.2-45 | 443 | * Sat Mar 21 2026 huzhangying <huzhangying@huawei.com> - 1.24.2-45 |
| 440 | - Type:CVE-2026-27139,CVE-2026-27142,CVE-2026-25679 | 444 | - Type:CVE-2026-27139,CVE-2026-27142,CVE-2026-25679 |
| 441 | - SUG:NA | 445 | - SUG:NA |