On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.
- https://groups.google.com/g/golang-announce/c/wkkO4P9stm0
- https://github.com/CodingSimia/jenkins-shiftleft
- https://github.com/LOURC0D3/CVE-2024-24787-PoC
- https://github.com/adegoodyer/kubernetes-admin-toolkit
- https://github.com/drewtwitchell/scancompare
- https://github.com/fkie-cad/nvd-json-data-feeds
- https://github.com/nomi-sec/PoC-in-GitHub