---
cve: "CVE-2025-61732"
severity: "HIGH"
cvss: 8.6
epss: "47%"
vendor: "Go toolchain"
kev: false
exploited: false
published: "2026-02-05 04:15:50"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T18:12:18+02:00"
---

# CVE-2025-61732

> 8.6 HIGH

## Beschreibung

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 96e4e2b1616c3c59577d48abcf2823bf1fdcd2e2 (Commit)
- eaf3bc799a221cc375f188e8699c9330c1caf40a (Commit)

## Referenzen

- <https://go.dev/cl/734220>
- <https://go.dev/issue/76697>
- <https://groups.google.com/g/golang-announce/c/K09ubi9FQFk>
- <https://pkg.go.dev/vuln/GO-2026-4433>
- <https://access.redhat.com/errata/RHSA-2026:10104>
- <https://access.redhat.com/errata/RHSA-2026:12282>
- <https://access.redhat.com/errata/RHSA-2026:14100>
- <https://access.redhat.com/errata/RHSA-2026:14774>
- <https://access.redhat.com/errata/RHSA-2026:15091>
- <https://access.redhat.com/errata/RHSA-2026:17598>
- <https://access.redhat.com/errata/RHSA-2026:21691>
- <https://access.redhat.com/errata/RHSA-2026:2706>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-61732) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
