CVE Vulnerabilities

CVE-2025-47906

Published: Sep 18, 2025 | Modified: Jan 27, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (, ., and ..), can result in the binaries listed in the PATH being unexpectedly returned.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.23.12 (excluding)
GoGolang1.24.0 (including)1.24.6 (excluding)
Red Hat Enterprise Linux 10RedHatgolang-0:1.24.6-1.el10_0*
Red Hat Enterprise Linux 8RedHatgo-toolset:rhel8-8100020251201162956.a3795dee*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatgo-toolset:rhel8-8020020251212160632.02f7cb7a*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatgo-toolset:rhel8-8040020251212161217.5081a262*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatgo-toolset:rhel8-8040020251212161217.5081a262*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatgo-toolset:rhel8-8060020251219132124.97d7f71f*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatgo-toolset:rhel8-8060020251219132124.97d7f71f*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatgo-toolset:rhel8-8060020251219132124.97d7f71f*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatgo-toolset:rhel8-8080020251215161342.17f3f959*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatgo-toolset:rhel8-8080020251215161342.17f3f959*
Red Hat Enterprise Linux 9RedHatgolang-0:1.24.6-1.el9_6*
Red Hat Enterprise Linux 9RedHatgo-rpm-macros-0:3.6.0-12.el9_7*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatgolang-0:1.17.13-8.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatgo-rpm-macros-0:3.0.9-12.el9_0*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatgolang-0:1.19.13-20.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatgo-rpm-macros-0:3.2.0-2.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatgolang-0:1.21.13-12.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatgo-rpm-macros-0:3.2.0-4.el9_4*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatgo-rpm-macros-0:3.6.0-11.el9_6*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:sha256:e3b3efcdd86f60b90664a249d45918b2ac5f45bae5eed5399e310d63e878b287*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:sha256:c5efe40fa2a6e98d7d3d6676befff0dbbd87b2887769bb7e5856c5b0b0ada125*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:sha256:72ac7afb81d57da7ee569790df6697785afe8f5b1379f3f6d3df5fc1ad741824*
Golang-1.23Ubuntuplucky*
Golang-1.24Ubuntuplucky*

References