Speaking of go, it looks they will be patching this as well.
Might it be a crypto bug, or logic bug (eg in x.509)? Is there code that's used by both OpenSSL and Go (eg assembly implementations of algorithms both imported or modeled after a reference)?
See screenshot of the slack conversation: https://paste.pics/f5622033ae711b36e0bbcda393a67866