Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Aug 30, 2017 | Apr 8, 2016 |
| Centos_linux | — | Upgrade git-svnUpgrade git-bzrUpgrade gitwebUpgrade gitUpgrade emacs-git-elUpgrade git-cvsUpgrade git-guiUpgrade emacs-gitUpgrade perl-Git-SVNUpgrade git-emailUpgrade gitkUpgrade perl-GitUpgrade git-allUpgrade git-p4Upgrade git-hgUpgrade git-daemon | Jul 6, 2016 | Mar 23, 2016 |
| Debian | — | Upgrade git | Mar 22, 2016 | Mar 19, 2016 |
| Freebsd | — | Upgrade git-liteUpgrade git-subversionUpgrade git-guiUpgrade git | Dec 10, 2025 | Mar 18, 2016 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Oct 30, 2017 | Apr 8, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade git | Nov 30, 2017 | Apr 8, 2016 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.7.4-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Apr 8, 2016 |
| Oracle_linux | — | Upgrade git-allUpgrade perl-GitUpgrade git-svnUpgrade git-emailUpgrade git-bzrUpgrade git-guiUpgrade git-daemonUpgrade emacs-gitUpgrade perl-Git-SVNUpgrade git-p4Upgrade gitUpgrade gitkUpgrade emacs-git-elUpgrade git-hgUpgrade gitwebUpgrade git-cvs | Apr 8, 2016 | Apr 8, 2016 |
| Suse | — | Upgrade gitkUpgrade git-daemonUpgrade git-cvsUpgrade git-emailUpgrade git-guiUpgrade git-webUpgrade gitUpgrade git-docUpgrade git-archUpgrade git-coreUpgrade git-svn | Mar 22, 2016 | Mar 16, 2016 |
| Ubuntu | — | Upgrade git | Mar 22, 2016 | Mar 21, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Apr 8, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub