golang / go

The Go programming language
https://go.dev
BSD 3-Clause "New" or "Revised" License
120.1k stars 17.24k forks source link

security: fix CVE-2024-24787 [1.22 backport] #67122

Closed gopherbot closed 1 week ago

gopherbot commented 2 weeks ago

@rolandshoemaker requested issue #67119 to be considered for backport to the next 1.22 minor release.

@gopherbot please open backports, this is a PRIVATE track security issue.

gopherbot commented 1 week ago

Change https://go.dev/cl/583796 mentions this issue: [release-branch.go1.22] cmd/go: disallow -lto_library in LDFLAGS

gopherbot commented 1 week ago

Closed by merging fa0292d252c762ff3de92b87d13417c50704f3a0 to release-branch.go1.22.