golang / go

The Go programming language
https://go.dev
BSD 3-Clause "New" or "Revised" License
120.1k stars 17.24k forks source link

security: fix CVE-2024-24787 [1.21 backport] #67121

Closed gopherbot closed 1 week ago

gopherbot commented 2 weeks ago

@rolandshoemaker requested issue #67119 to be considered for backport to the next 1.21 minor release.

@gopherbot please open backports, this is a PRIVATE track security issue.

gopherbot commented 1 week ago

Change https://go.dev/cl/583795 mentions this issue: [release-branch.go1.21] cmd/go: disallow -lto_library in LDFLAGS

gopherbot commented 1 week ago

Closed by merging a79ea27e36a1c56ae48dc36ce48549c9787ca4b7 to release-branch.go1.21.