[Git][security-tracker-team/security-tracker][master] Track fixed version for golang-1.24 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 28 07:48:21 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8b75038f by Salvatore Bonaccorso at 2025-09-28T08:42:41+02:00
Track fixed version for golang-1.24 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18237,7 +18237,7 @@ CVE-2023-41519 (Student Attendance Management System v1 was discovered to contai
 CVE-2023-40992 (Hospital Management System 4 is vulnerable to a SQL injection in /Hosp ...)
 	NOT-FOR-US: Hospital Management System
 CVE-2025-47907 (Cancelling a query (e.g. by cancelling the context passed to one of th ...)
-	- golang-1.24 <unfixed> (bug #1110949)
+	- golang-1.24 1.24.7-1 (bug #1110949)
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.23 <unfixed> (bug #1110950)
 	- golang-1.19 <removed>
@@ -18249,7 +18249,7 @@ CVE-2025-47907 (Cancelling a query (e.g. by cancelling the context passed to one
 	NOTE: https://github.com/golang/go/commit/83b4a5db240960720e51b7d5a6da1f399bd868ee (go1.24.6)
 	NOTE: https://github.com/golang/go/commit/8a924caaf348fdc366bab906424616b2974ad4e9 (go1.23.12)
 CVE-2025-47906 (If the PATH environment variable contains paths which are executables  ...)
-	- golang-1.24 <unfixed> (bug #1110947)
+	- golang-1.24 1.24.7-1 (bug #1110947)
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.23 <unfixed> (bug #1110948)
 	- golang-1.19 <removed>
@@ -26505,7 +26505,7 @@ CVE-2025-27165 (Substance3D - Stager versions 3.1.2 and earlier are affected by
 CVE-2024-56468 (IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 could ...)
 	NOT-FOR-US: IBM
 CVE-2025-4674 (The go command may execute unexpected commands when operating in untru ...)
-	- golang-1.24 <unfixed> (bug #1109109)
+	- golang-1.24 1.24.7-1 (bug #1109109)
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.23 <unfixed> (bug #1109110)
 	- golang-1.19 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b75038f5b5c85113e6335262e36ae88d8cbdc62

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b75038f5b5c85113e6335262e36ae88d8cbdc62
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250928/54d07f25/attachment.htm>


More information about the debian-security-tracker-commits mailing list