← Back

CVE-2025-0913

nvd nist
Published: Jun 11, 2025Modified: Aug 8, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

Affected (2)

Products: Golang: Go
1 product
Go
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Golang
Before 1.23.10
From 1.24.0 to 1.24.4
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (4)

Source: security@golang.org
Issue Tracking
Source: security@golang.org
Issue Tracking
Source: security@golang.org
Mailing List
Source: security@golang.org
Vendor Advisory

Timeline

No history available yet.