[CLSA-2025:1756931716] golang: Fix of CVE-2025-4674
Type:
security
Severity:
Important
Release date:
2025-09-03 20:35:19 UTC
Description:
- CVE-2025-4674: disallow multiple VCS metadata dirs in one module to prevent VCS injection attacks
Updated packages:
  • go-toolset-1.22.5-1.el9_2.tuxcare.els6.x86_64.rpm
    sha:d252103966ed0b91a841f8d81cf3f0889287b43f659374a1df542dea11bb022b
  • golang-1.22.5-1.el9_2.tuxcare.els6.x86_64.rpm
    sha:4a1ba8eab7a68f00fd2ac95a7df3159eb0a25e57eb904c17d96ddaffb8474198
  • golang-bin-1.22.5-1.el9_2.tuxcare.els6.x86_64.rpm
    sha:de25d7dddeae744e4143091a4447a8626d435a982fd50803d1db52b43c9e6d10
  • golang-docs-1.22.5-1.el9_2.tuxcare.els6.noarch.rpm
    sha:299e33b80948f65187572c5241b8063077d895025a80e225a4d095584fe10318
  • golang-misc-1.22.5-1.el9_2.tuxcare.els6.noarch.rpm
    sha:264f2b6448e1f58314491ac404cfb72a636de48472521e3f8c0b60f00dac6834
  • golang-src-1.22.5-1.el9_2.tuxcare.els6.noarch.rpm
    sha:5e7c09cad2db5fd70223f4152e468268c7cce8ad3c76dd24e576b10e7ecd0f5f
  • golang-tests-1.22.5-1.el9_2.tuxcare.els6.noarch.rpm
    sha:8e0cd0ac08f89d74d9a9aecd50d1fc032f7bbc51312919f94cac0bff78c086c0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.