os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Aug 8, 2025 | Jun 11, 2025 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Enterprise to version 9.4.8Upgrade Splunk Enterprise to version 9.4.9Upgrade Splunk Enterprise to version 9.3.9Upgrade Splunk Enterprise to version 10.0.3Upgrade Splunk Enterprise to version 9.2.12Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Enterprise to version 10.0.4 | Jul 30, 2026 | Jun 11, 2025 |
| Suse | — | Upgrade govulncheck-vulndbUpgrade go1.24-openssl-raceUpgrade go1.24-opensslUpgrade go1.23-openssl-docUpgrade go1.23-openssl-raceUpgrade go1.24-raceUpgrade go1.24-libstdUpgrade go1.24Upgrade go1.23-raceUpgrade go1.24-openssl-docUpgrade go1.23-opensslUpgrade go1.23Upgrade go1.24-docUpgrade go1.23-doc | Jun 10, 2025 | Jun 10, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 15, 2026 | Jun 11, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub