Executive brief
A vulnerability in the Go programming language's standard library could allow an attacker to modify file permissions outside of an intended directory on Linux systems. By quickly replacing a file with a symbolic link during a specific operation, an attacker could trick the system into changing the permissions of sensitive files they should not have access to. This could lead to unauthorized data access or system instability, though it requires high privileges and precise timing to execute.
Technical details
A race condition exists in the Go standard library's internal/syscall/unix package on Linux. The Root.Chmod function uses the fchmodat syscall with the AT_SYMLINK_NOFOLLOW flag to prevent symlink traversal; however, the Linux kernel silently ignores this flag for fchmodat. While Go performs a pre-check to ensure the target is not a symlink, an attacker can replace the target file with a symlink between the check and the actual syscall (TOCTOU). This allows the chmod operation to be applied to a target outside the restricted root. The issue is resolved in Go 1.25.9 and 1.26.2 by using the fchmodat2 syscall or a /proc/self/fd workaround.
Affected products
- Go Project Go standard library < 1.25.9, >= 1.26.0-0 < 1.26.2
Timeline
- 2026-03-23: disclosed: Issue opened on Go GitHub repository
- 2026-04-07: advisory: Go Project published vulnerability report GO-2026-4864
- 2026-04-08: patched: CVE published and fixes released in Go 1.25.9 and 1.26.2