On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.
History

Mon, 09 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library os
Vendors & Products Go Standard Library
Go Standard Library os

Fri, 06 Mar 2026 21:45:00 +0000

Type Values Removed Values Added
Description On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.
Title FileInfo can escape from a Root in os
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published: 2026-03-06T21:28:14.451Z

Updated: 2026-03-09T14:53:58.363Z

Reserved: 2026-02-17T19:57:28.435Z

Link: CVE-2026-27139

cve-icon Vulnrichment

Updated: 2026-03-09T14:53:42.735Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-06T22:16:01.070

Modified: 2026-03-09T15:15:57.150

Link: CVE-2026-27139

cve-icon Redhat

No data.