CVE-2025-47907

EUVD-2025-23921
Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
golanggo
𝑥
< 1.23.12
golanggo
1.24.0 ≤
𝑥
< 1.24.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
postponed
golang-1.19
bookworm
no-dsa
golang-1.24
trixie
no-dsa
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
go-toolset
RHEL 9
0:1.24.6-1.el9_6
fixed
golang
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-bin
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-docs
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-misc
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-race
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-src
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-tests
RHEL 9
0:1.24.6-1.el9_6
fixed
podman
RHEL 9
6:5.6.0-6.el9_7
fixed
podman-docker
RHEL 9
6:5.6.0-6.el9_7
fixed
podman-plugins
RHEL 9
6:5.6.0-6.el9_7
fixed
podman-remote
RHEL 9
6:5.6.0-6.el9_7
fixed
podman-tests
RHEL 9
6:5.6.0-6.el9_7
fixed