{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-07T19:41:18Z",
  "bugzilla" : {
    "description" : "cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack",
    "id" : "2467813",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2467813"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-59",
  "details" : [ "The \"go bug\" command writes to two files with predictable names in the system temporary directory (for example, \"/tmp\"). An attacker with access to the temporary directory can create a symlink in one of these names, causing \"go bug\" to overwrite the target of the symlink.", "A flaw was found in the 'go bug' command within the Go programming language tools. This command writes to temporary files with predictable names. A local attacker with access to the system's temporary directory could exploit this by creating a symbolic link (symlink) with one of these predictable names. This would cause the 'go bug' command to overwrite the target of the symlink, potentially leading to arbitrary file overwrite." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-06-01T00:00:00Z",
    "advisory" : "RHSA-2026:22120",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "golang-0:1.26.3-4.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49702",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "golang-0:1.26.5-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-06-01T00:00:00Z",
    "advisory" : "RHSA-2026:22112",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "go-toolset:rhel8-8100020260518131104.a3795dee"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-06-01T00:00:00Z",
    "advisory" : "RHSA-2026:22121",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "golang-0:1.26.3-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61253",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "golang-0:1.26.5-1.el9_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-20T00:00:00Z",
    "advisory" : "RHSA-2026:57649",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "golang-0:1.26.5-1.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49712",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "golang-0:1.26.5-1.el9_6"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.11.0",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:57194",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.11::el9",
    "package" : "multicluster-engine/hypershift-addon-rhel9-operator:1786912006"
  } ],
  "package_state" : [ {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/addon-manager-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/backplane-rhel9-operator",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/clusterlifecycle-state-metrics-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/maestro-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/managedcluster-import-controller-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/multicloud-manager-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/placement-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/registration-operator-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Under investigation",
    "package_name" : "multicluster-engine/work-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "OpenShift API for Data Protection",
    "fix_state" : "Under investigation",
    "package_name" : "oadp/oadp-velero-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_api_data_protection:1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/acm-governance-policy-addon-controller-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/acm-governance-policy-framework-addon-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/config-policy-controller-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/governance-policy-propagator-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Under investigation",
    "package_name" : "rhacm2/klusterlet-addon-controller-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Under investigation",
    "package_name" : "openshift4/ose-hypershift-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-39819\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-39819\nhttps://go.dev/cl/763882\nhttps://go.dev/issue/78584\nhttps://groups.google.com/g/golang-announce/c/qcCIEXso47M\nhttps://pkg.go.dev/vuln/GO-2026-4978" ],
  "name" : "CVE-2026-39819",
  "csaw" : false
}