A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-76743.json"