# github.com/klauspost/cpuid/v2@v2.2.9 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:10:37.000Z
- Files reviewed: 11
- Findings: 2 medium, 2 low severity findings
- Report: https://security.togoder.click/go/github.com/klauspost/cpuid/v2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/klauspost/cpuid/v2@v2.2.9 on Oct 5, 2026. An AI review of 11 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] import-time execution

Finding ID: `NPS-6C3311CD968E`

File: `cpuid.go:293`

The package runs init() at import time which calls initCPU() and Detect(). Detect() parses command-line flags (cpu.disable, cpu.features, cpu.arm) and may call os.Exit(1) if -cpu.features is set. This is a behavior that modifies process behavior and can terminate the host program unexpectedly based solely on ambient flag values, which is unusual for a library.

### [medium] process termination from library code

Finding ID: `NPS-CA02678BEF26`

File: `cpuid.go:316`

The Detect() function calls os.Exit(1) when the -cpu.features flag is enabled. Library code should not terminate the calling process; this can be abused or cause unexpected denial of service when flags are supplied by a parent process.

### [low] global flag registration side effect

Finding ID: `NPS-C296ED3693AA`

File: `cpuid.go:352`

Flags() registers global command-line flags (cpu.disable, cpu.features, cpu.arm) which, if called before flag.Parse, influences parsing of the host application's command line. This is a side effect not typical for a CPU detection library and could interfere with the host program.

### [low] use of go:linkname

Finding ID: `NPS-4F4592837213`

File: `os_unsafe_linux_arm64.go:9`

This file uses //go:linkname to access the unexported symbol internal/cpu.HWCap from the Go standard library. While not inherently malicious, go:linkname is a powerful unsafe mechanism that bypasses Go's type safety and module boundaries. It relies on undocumented internal implementation details, may break across Go versions, and can be abused to access or alter internal runtime/stdlib state. It is gated behind a build tag (!nounsafe), which is a reasonable mitigation. No data exfiltration, credential harvesting, process spawning, or dynamic code execution is present.

## Files reviewed

- `cpuid.go` (medium): The cpuid library contains import-time CPU detection and command-line flag/exit side effects, but no data exfiltration, credential harvesting, obfuscation, network activity, or process spawning was observed.
- `os_unsafe_linux_arm64.go` (medium): The file is not malicious but uses the unsafe go:linkname directive to access an internal standard library symbol, which warrants caution due to its fragility and potential for abuse.
- `cmd/cpuid/main.go` (safe): No malicious patterns detected
- `detect_arm64.go` (safe): No malicious patterns detected
- `detect_ref.go` (safe): No malicious patterns detected; the file contains only stub implementations for CPU feature detection on unsupported architectures.
- `detect_x86.go` (safe): No malicious patterns detected; the file contains only CPU feature detection declarations and initialization for x86 architectures.
- `featureid_string.go` (safe): No malicious patterns detected
- `os_darwin_arm64.go` (safe): No malicious patterns detected; the code only reads macOS sysctl values to populate CPU feature information.
- `os_linux_arm64.go` (safe): No malicious patterns detected
- `os_other_arm64.go` (safe): No malicious patterns detected; the file only reads CPU core counts via runtime.NumCPU for ARM64 non-Linux/non-Darwin platforms.
- `os_safe_linux_arm64.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
