CVE-2025-0913

Aliases:GO-2025-3750BIT-golang-2025-0913CGA-23qx-fw3j-r397CGA-28m3-9j63-rprrCGA-2fx4-7fmh-8f5fCGA-2g9r-cf9v-w8gvCGA-2j85-8vjw-v68hCGA-2vqc-x9gm-59p7CGA-2xv6-r85h-fmccCGA-37rx-28w8-322wCGA-3mcx-3p22-8qvfCGA-3q3p-h533-4cq2CGA-3v2c-9pxj-jc8cCGA-4pfx-r7gr-vc9hCGA-4q8h-v9g2-8wqxCGA-537c-f2q7-c5c4CGA-592h-96q2-95wvCGA-5cfg-gf6m-9w5mCGA-5h83-h55q-pw2mCGA-5x85-m6wp-h94vCGA-627c-cf77-4mp2CGA-63r7-f65x-q883CGA-68cf-3rwr-27vcCGA-6hqj-394v-vm6mCGA-6j8m-99mx-jr6jCGA-6w23-wpjf-qprfCGA-6xvv-h46j-chf8CGA-79x5-g86h-j6gxCGA-7gm4-g77w-r7qwCGA-84vv-66hf-9gmgCGA-8958-q2cf-m8wxCGA-89fp-295r-cmx9CGA-8fjg-6wrv-ggxfCGA-8fjm-cjrc-2qcwCGA-8hh8-hx5w-7g9qCGA-92hq-7vw4-6rw6CGA-949h-hx79-w8x2CGA-9gh8-wg65-h543CGA-9h57-xcg6-7qx3CGA-9m9w-fr22-cj84CGA-9p99-xvqr-gcvqCGA-9xjr-j7hc-pr6hCGA-c25j-99rh-fpwxCGA-c863-h7mj-wmgqCGA-ccx8-w925-fw69CGA-cp2x-9cwh-r8fjCGA-cvv9-x54x-qgq6CGA-cwgc-4fm6-23grCGA-f34p-3584-4rrhCGA-f3pp-v754-5cg5CGA-fp6m-r66g-4m3qCGA-fxw9-gxwr-x24cCGA-g3qv-47mq-5f3mCGA-g3x3-8x25-f5cfCGA-g488-r6jx-6968CGA-g646-4jwv-98x7CGA-g872-c6fj-r36cCGA-g8fm-pfw2-mvh4CGA-g9fx-pfmw-h3v3CGA-gmc6-j365-x685CGA-h4p4-xx94-gvxwCGA-h4v7-hrv4-w3j5CGA-j3fq-9wf8-4rcjCGA-j3hm-37qw-658mCGA-jfgc-fc74-jfx3CGA-jp9c-ghgv-jmcqCGA-m99q-4hjm-66j5CGA-mhj4-gw39-37j8CGA-mmv9-x82m-7p43CGA-mq52-72xw-mxq5CGA-p4gq-q3c8-w8hqCGA-p8xf-xrw6-5c7gCGA-p9hp-f437-h9ppCGA-4m9c-pjrf-wqx6CGA-79fr-vv3q-wwfgCGA-9j3g-px5p-5x4wCGA-c4h6-5qmw-wmc3CGA-p3wc-fp2c-mgq4CGA-ppc4-pmfr-29c4CGA-q77q-45pc-29hfCGA-qh8c-c3rg-vm8pCGA-qmpv-4vpx-9x7vCGA-qpvg-9wpj-pvgvCGA-qqxf-fm4x-23cgCGA-qrxf-fjhj-h3mjCGA-qvjg-45w5-x96xCGA-qw24-fjg4-w92xCGA-qwcc-fjqw-7977CGA-qx2j-pmc7-pm77CGA-r4c6-9736-fq5rCGA-r8c3-gcq8-vw37CGA-rmrg-5fhr-2vr3CGA-rv8v-hhwx-2cr5CGA-rvvx-mm4v-2fc5CGA-rx4m-c9jq-9qc7CGA-rxvm-j8fj-f5q5CGA-v6cc-2656-m7jpCGA-vjgf-47x9-jw7fCGA-vjrx-35gq-83wgCGA-vw68-g2mq-62frCGA-w6f9-hhv5-84h7CGA-w8ww-p9gf-vm92CGA-w93g-44r6-c3mrCGA-whjh-mmjr-jh5hCGA-whwr-fjhh-jjjhCGA-wjxf-2c2j-32mwCGA-wm8j-vj64-3rv3CGA-wv4v-r9mj-h9qcCGA-wvq8-v5cm-ff7rCGA-ww6m-gr26-8v7xCGA-x662-mw8w-3mwxCGA-x9w4-vwm9-hhm6CGA-xgfq-2vm2-7jj5CGA-xhcc-q5v9-fj7fCGA-xhpc-5wrr-pr29CGA-xq5j-f576-fqp7CGA-4mhw-52r2-39vjCGA-5833-9h59-25cv
Analyzed
Published: 11 Jun 2025, 17:17
Last modified:11 Jun 2025, 17:37

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.31% LOW
0% probability +0.30%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Jun 2025, 17:17
Published
Vulnerability first disclosed
11 Jun 2025, 17:37
Last Modified
Vulnerability information updated

Description

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.31% Percentile: 25%

Techniques & Countermeasures

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Systems

  • chainguardgo-1.20

    < 1.20.14-r9

  • chainguardgo-1.22

    < 1.22.12-r8

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    all

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • chainguardnewrelic-fluent-bit-output

    < 2.4.0-r5

  • chainguardnvidia-nsight-compute-12.8

    < 2025.1.1.2-r7

  • chainguardnvidia-nsight-compute-12.9

    < 2025.2.1.3-r5 | all

  • chainguardnvidia-nsight-compute-13.0

    < 2025.3.0.19-r2

  • chainguardnvidia-nsight-compute-13.1

    < 2025.4.1.2-r0 | < 2025.3.0.19-r0

  • wolfigo-1.20

    < 1.20.14-r9

  • wolfigo-1.22

    < 1.22.12-r8

  • wolfikatib-earlystopping

    < 0.19.0-r31

  • wolfikatib-suggestion-goptuna-compat

    all

  • wolfikatib-suggestion-hyperband

    < 0.19.0-r31

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • wolfikatib-suggestion-nas-darts

    < 0.19.0-r31

  • wolfikatib-suggestion-nas-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-optuna-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-pbt-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-skopt-enas

    < 0.19.0-r31

  • wolfikatib-tfevent-metricscollector

    < 0.19.0-r31

  • wolfinewrelic-fluent-bit-output

    < 2.4.0-r5

  • go standard libraryos

    < 1.23.10 | ≥ 1.24.0-0, < 1.24.4

  • go standard librarysyscall

    < 1.23.10 | ≥ 1.24.0-0, < 1.24.4

  • golanggo

    < 1.23.10 | ≥ 1.24.0, < 1.24.4

  • Gostdlib

    ≥ 1.24.0-0, < 1.24.4

References (7)