Executive brief
A vulnerability in the Go programming language compiler could allow for memory corruption in compiled applications. The Go compiler, which translates human-readable code into machine instructions, fails to correctly handle certain memory operations when specific interface conversions are used. This could lead to unpredictable application behavior or crashes in software built with affected versions of the Go toolchain.
Technical details
A type confusion vulnerability (CWE-843) exists in the Go compiler's 'cmd/compile' component. The compiler is designed to unwrap pointers that are operands of a memory move to determine if the source and destination overlap; however, a no-op interface conversion prevents this unwrapping. This failure leads to an incorrect determination that moves are non-overlapping, causing the compiler to generate unsafe machine code that results in memory corruption at runtime. The issue affects the Go toolchain versions prior to 1.25.9 and 1.26.x versions prior to 1.26.2. Patches have been released in Go 1.25.9 and 1.26.2.
Affected products
- Google Go toolchain (cmd/compile) < 1.25.9, >= 1.26.0-0 < 1.26.2
Timeline
- 2026-03-25: disclosed: Issue reported to Go project by Jakub Ciolek
- 2026-04-07: advisory: Initial advisory published by Go Project
- 2026-04-08: patched: CVE published and fixes available in Go 1.25.9 and 1.26.2