Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade git | Feb 9, 2018 | Oct 14, 2017 |
| Debian | — | Upgrade git | Jul 30, 2024 | Oct 14, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Sep 12, 2019 | Oct 14, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade git | Sep 25, 2019 | Oct 14, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git | Sep 12, 2019 | Oct 14, 2017 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.15.0-0.175.3.28.0.1.0 on Solaris 11.3 | Feb 6, 2018 | Oct 14, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 12, 2017 |
| Suse | — | Upgrade git-coreUpgrade git-credential-libsecretUpgrade git-docUpgrade gitUpgrade git-archUpgrade git-webUpgrade git-credential-gnome-keyringUpgrade git-svnUpgrade git-daemonUpgrade git-p4Upgrade git-emailUpgrade gitkUpgrade git-cvsUpgrade git-gui | Apr 11, 2018 | Oct 14, 2017 |
| Ubuntu | — | Upgrade git | Dec 4, 2018 | Oct 14, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Oct 14, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub