Image reports › golang
golang — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/golang · Debian GNU/Linux 13 (trixie)
Latest: golang:latest · checked 2026-09-25
Not FIPS-ready
No. golang:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 193 known vulnerabilities
193 known vulnerabilities in 52 packages (5 high); none has a fix available yet.
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | CVE-2019-19449 | linux-libc-dev 6.12.107-1 | no fix yet | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated). |
| high | CVE-2019-19814 | linux-libc-dev 6.12.107-1 | no fix yet | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this. |
| high | CVE-2021-3847 | linux-libc-dev 6.12.107-1 | no fix yet | An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system. |
| high | CVE-2024-21803 | linux-libc-dev 6.12.107-1 | no fix yet | Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C. |
| high | CVE-2021-3864 | linux-libc-dev 6.12.107-1 | no fix yet | A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a resul |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | C 193 | 2026-09-25 | Full report |