libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ezaUpgrade libgit2 | Aug 22, 2024 | Feb 6, 2024 |
| Amazon Linux Ami 2 | — | Upgrade rustfmtUpgrade rust-toolset-srpm-macrosUpgrade rustUpgrade rust-std-staticUpgrade rust-debugger-commonUpgrade rust-analysisUpgrade rust-debuginfoUpgrade rust-srcUpgrade rust-gdbUpgrade rust-docUpgrade rust-analyzerUpgrade clippyUpgrade rust-toolsetUpgrade cargo | Mar 19, 2024 | Feb 6, 2024 |
| Amazon_linux | — | Upgrade rust | Jan 25, 2025 | Feb 6, 2024 |
| Amazon_linux_2023 | — | Upgrade libgit2-debuginfoUpgrade rust-gdbUpgrade cargo-debuginfoUpgrade libgit2-develUpgrade rustfmtUpgrade clippy-debuginfoUpgrade libgit2Upgrade rust-debugger-commonUpgrade rust-analyzerUpgrade rust-std-static-wasm32-wasiUpgrade clippyUpgrade rust-analyzer-debuginfoUpgrade cargoUpgrade rust-debuginfoUpgrade libgit2-debugsourceUpgrade rustfmt-debuginfoUpgrade rust-debugsourceUpgrade rustUpgrade rust-srcUpgrade rust-lldbUpgrade rust-docUpgrade rust-std-static-wasm32-unknown-unknownUpgrade rust-analysisUpgrade rust-std-static | Feb 17, 2025 | Feb 6, 2024 |
| Debian | — | Upgrade libgit2 | Feb 12, 2024 | Feb 6, 2024 |
| Freebsd | — | Upgrade libgit2Upgrade eza | Feb 9, 2024 | Feb 8, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libgit2 | Jul 23, 2024 | Feb 6, 2024 |
| Suse | — | Upgrade git-daemonUpgrade git-credential-libsecretUpgrade gitUpgrade git-p4Upgrade libgit2-toolsUpgrade libgit2-1_9Upgrade git-archUpgrade git-emailUpgrade libgit2-1_3Upgrade libgit2-26Upgrade git-cvsUpgrade git-credential-gnome-keyringUpgrade libgit2-develUpgrade libgit2-1_7Upgrade git-docUpgrade git-coreUpgrade libgit2-28Upgrade libgit2-24Upgrade gitkUpgrade git-webUpgrade git-svnUpgrade libgit2-1_3-32bitUpgrade perl-GitUpgrade git-gui | Jul 23, 2024 | Feb 6, 2024 |
| Ubuntu | — | Upgrade libgit2-24 (Ubuntu Pro)Upgrade libgit2-28Upgrade libgit2-26 (Ubuntu Pro)Upgrade libgit2-1.5Upgrade libgit2-1.1 | Mar 6, 2024 | Feb 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub