Re: [yocto] go regression in scarthgap related to CVE-2025-61726 patch

"Yoann Congal" <[email protected]> Wed, 11 Mar 2026 20:16:56 +0100
Newsgroups org.yoctoproject.lists.yocto
Message-ID <[email protected]>
On Wed Mar 11, 2026 at 7:18 PM CET, Cedric Veilleux via lists.yoctoproject.org wrote:
> After the recent golang patchset in scarthgap, go programs are crashing with:
>
>> panic: godebug: Value of name not listed in godebugs.All: urlmaxqueryparams goroutine 1 [running]: internal/godebug
>
> This is observed in the podman recipe from meta-virtualization but I don't think it is related to podman only.
>
> I've traced it to this commit:
>
>> commit 242963f4cd1597d31a3efae2422016bf888c6e25
>> Author: Deepak Rathore <[email protected]>
>> Date:   Wed Feb 11 20:59:00 2026 -0800
>> 
>>     go 1.22.12: Fix CVE-2025-61726
>
> Removing this patch fixes the issue.

Is this problem related to this patch under review?
go: Fix CVE-2025-61726.patch variable ordering
https://git.openembedded.org/openembedded-core-contrib/commit/?h=stable/scarthgap-nut&id=9605a264c87b5c7ce26eeec902448b0892f8af1a

Could you try to see if that fixes your problem and report back?

Thanks!
-- 
Yoann Congal
Smile ECS