File _patchinfo of Package patchinfo.40087
<patchinfo incident="40087">
<issue tracker="bnc" id="1247720">VUL-0: CVE-2025-47907: go1.23,go1.24,go1.25: database/sql: incorrect results returned from Rows.Scan</issue>
<issue tracker="bnc" id="1247719">VUL-0: CVE-2025-47906: go1.23,go1.24,go1.25: os/exec: LookPath may return unexpected paths</issue>
<issue tracker="bnc" id="1229122">go1.23 release tracking</issue>
<issue tracker="cve" id="2025-47907"/>
<issue tracker="cve" id="2025-47906"/>
<packager>jfkw</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for go1.23</summary>
<description>This update for go1.23 fixes the following issues:
Updated to go1.23.12 (released 2025-08-06) (bsc#1229122):
- CVE-2025-47906: Fixed lookPath may return unexpected paths in os/exec (bsc#1247719)
- CVE-2025-47907: Fixed incorrect results returned from Rows.Scan in database/sql (bsc#1247720)
Other fixes:
- runtime: use-after-free of allpSnapshot in findRunnable
- runtime: segfaults in runtime.(*unwinder).next
- cmd/go: TestScript/build_trimpath_cgo fails to decode dwarf on release-branch.go1.23
- cmd/cgo/internal/testsanitizers: failures with signal: segmentation fault or exit status 66
</description>
</patchinfo>