Cryptopsyby CloudTrace

Image reports › golang

golang — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/golang · Debian GNU/Linux 13 (trixie)

Latest: golang:latest · checked 2026-09-25

Not FIPS-ready

No. golang:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 193 known vulnerabilities

193 known vulnerabilities in 52 packages (5 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
highCVE-2019-19449linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).
highCVE-2019-19814linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
highCVE-2021-3847linux-libc-dev 6.12.107-1no fix yetAn unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.
highCVE-2024-21803linux-libc-dev 6.12.107-1no fix yetUse After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C.
highCVE-2021-3864linux-libc-dev 6.12.107-1no fix yetA flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a resul

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyC 1932026-09-25Full report