vulnerability
Amazon Linux 2023: CVE-2025-61731: Medium priority package update for amazon-ecr-credential-helper (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:M/Au:N/C:C/I:C/A:C) | Jan 28, 2026 | Feb 10, 2026 | Mar 31, 2026 |
Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Jan 28, 2026
Added
Feb 10, 2026
Modified
Mar 31, 2026
Description
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
A flaw was found in cmd/go. An attacker can exploit this by building a malicious Go source file that uses the '#cgo pkg-config:' directive. This allows the attacker to write to an arbitrary file with partial control over its content, by providing a '--log-file' argument to the pkg-config command. This vulnerability can lead to arbitrary file write.
A flaw was found in cmd/go. An attacker can exploit this by building a malicious Go source file that uses the '#cgo pkg-config:' directive. This allows the attacker to write to an arbitrary file with partial control over its content, by providing a '--log-file' argument to the pkg-config command. This vulnerability can lead to arbitrary file write.
Solutions
amazon-linux-2023-upgrade-amazon-cloudwatch-agentamazon-linux-2023-upgrade-amazon-ecr-credential-helperamazon-linux-2023-upgrade-captreeamazon-linux-2023-upgrade-captree-debuginfoamazon-linux-2023-upgrade-cni-pluginsamazon-linux-2023-upgrade-cni-plugins-debuginfoamazon-linux-2023-upgrade-cni-plugins-debugsourceamazon-linux-2023-upgrade-containerdamazon-linux-2023-upgrade-containerd-debuginfoamazon-linux-2023-upgrade-containerd-debugsourceamazon-linux-2023-upgrade-containerd-stressamazon-linux-2023-upgrade-containerd-stress-debuginfoamazon-linux-2023-upgrade-golangamazon-linux-2023-upgrade-golang-binamazon-linux-2023-upgrade-golang-docsamazon-linux-2023-upgrade-golang-miscamazon-linux-2023-upgrade-golang-sharedamazon-linux-2023-upgrade-golang-srcamazon-linux-2023-upgrade-golang-testsamazon-linux-2023-upgrade-golistamazon-linux-2023-upgrade-golist-debuginfoamazon-linux-2023-upgrade-golist-debugsourceamazon-linux-2023-upgrade-libcapamazon-linux-2023-upgrade-libcap-debuginfoamazon-linux-2023-upgrade-libcap-debugsourceamazon-linux-2023-upgrade-libcap-develamazon-linux-2023-upgrade-libcap-staticamazon-linux-2023-upgrade-nerdctlamazon-linux-2023-upgrade-oci-add-hooksamazon-linux-2023-upgrade-oci-add-hooks-debuginfoamazon-linux-2023-upgrade-oci-add-hooks-debugsourceamazon-linux-2023-upgrade-runfinch-finchamazon-linux-2023-upgrade-soci-snapshotter
References
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.