{"id":"CVE-2026-39817","title":"cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)","summary":"A flaw was found in the \"go tool pack\" subcommand, a component of the Go programming language tools. This vulnerability allows an attacker to craft a malicious archive file. When this archive is extracted using the \"pack\" subcommand, it ca…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N","cvssSource":"vendor","cwe":"CWE-22","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream (v. 8)","affected":["hardened_images","multicluster_engine_for_kubernetes","advanced_cluster_management_for_kubernetes 2","openshift_container_platform 4","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","openshift_api_for_data_protection 1.6","multicluster_engine_for_kubernetes 2.11"],"patched":["enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","openshift_api_for_data_protection 1.6","hardened_images","multicluster_engine_for_kubernetes 2.11"],"published":"2026-05-07","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:38:11+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39817.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39817.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-39817"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467825"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-39817"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39817"},{"url":"https://go.dev/cl/767520"},{"url":"https://go.dev/issue/78778"},{"url":"https://groups.google.com/g/golang-announce/c/qcCIEXso47M"},{"url":"https://pkg.go.dev/vuln/GO-2026-4979"},{"url":"https://access.redhat.com/errata/RHSA-2026:49702"},{"url":"https://access.redhat.com/errata/RHSA-2026:22120"},{"url":"https://access.redhat.com/errata/RHSA-2026:22112"},{"url":"https://access.redhat.com/errata/RHSA-2026:61253"},{"url":"https://access.redhat.com/errata/RHSA-2026:57649"},{"url":"https://access.redhat.com/errata/RHSA-2026:49712"},{"url":"https://access.redhat.com/errata/RHSA-2026:22121"},{"url":"https://access.redhat.com/errata/RHSA-2026:43692"},{"url":"https://access.redhat.com/errata/RHSA-2026:62391"},{"url":"https://access.redhat.com/errata/RHSA-2026:66561"},{"url":"https://access.redhat.com/errata/RHSA-2026:57194"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.0017,"epssPercentile":0.06712,"aliases":["GO-2026-4979","BIT-golang-2026-39817"],"ecosystem":"go","ingestedAt":"2026-08-26T19:27:02.399Z","slug":"CVE-2026-39817","body":"## Overview\n\nA flaw was found in the \"go tool pack\" subcommand, a component of the Go programming language tools. This vulnerability allows an attacker to craft a malicious archive file. When this archive is extracted using the \"pack\" subcommand, it can lead to arbitrary file writes on the filesystem, potentially allowing an attacker to create or modify files in unintended locations.\n\n## Vendor advisories\n\n- **RHSA-2026:49702** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49702)\n- **RHSA-2026:22120** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22120)\n- **RHSA-2026:22112** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22112)\n- **RHSA-2026:61253** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61253)\n- **RHSA-2026:57649** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57649)\n- **RHSA-2026:49712** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49712)\n- **RHSA-2026:22121** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22121)\n- **RHSA-2026:43692** · Red Hat · fixed in: OpenShift API for Data Protection 1.6 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43692)\n- **RHSA-2026:62391** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62391)\n- **RHSA-2026:66561** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66561)\n- **RHSA-2026:57194** · Red Hat · fixed in: multicluster engine for Kubernetes 2.11 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57194)\n- **Red Hat VEX** · Moderate · affected: Red Hat Hardened Images, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Hardened Images · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39817.json)\n\n**cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction** — rated Moderate by Red Hat. Released 2026-05-07, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Hardened Images\n- Multicluster Engine for Kubernetes\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat OpenShift Container Platform 4\n\nFixed:\n\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream E4S (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- OpenShift API for Data Protection 1.6\n- Red Hat Hardened Images\n- multicluster engine for Kubernetes 2.11\n\nNo fix planned:\n\n- Red Hat Hardened Images\n\nNot affected:\n\n- OpenShift API for Data Protection 1.6\n- multicluster engine for Kubernetes 2.11\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:49702\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22120\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22112\n\n## Package advisory (CVE-2026-39817)\n\nAffected packages:\n\n- `toolchain >= 1.26.0-0, < 1.26.3`\n\nPatched in:\n\n- `toolchain 1.26.3`\n\nSource: https://osv.dev/vulnerability/GO-2026-4979","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":5146,"id":"CVE-2026-39817","ts":1788887250888,"field":"cvss","old":null,"new":"5.9"},{"seq":5145,"id":"CVE-2026-39817","ts":1788887250888,"field":"severity","old":"none","new":"medium"},{"seq":4029,"id":"CVE-2026-39817","ts":1788886366794,"field":"cvss","old":"5.9","new":null},{"seq":4028,"id":"CVE-2026-39817","ts":1788886366794,"field":"severity","old":"medium","new":"none"},{"seq":3161,"id":"CVE-2026-39817","ts":1788883133139,"field":"cvss","old":null,"new":"5.9"},{"seq":3160,"id":"CVE-2026-39817","ts":1788883133139,"field":"severity","old":"none","new":"medium"}]}