Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | amazon-linux-upgrade-git | Feb 9, 2018 | Oct 14, 2017 |
| Debian | debian-upgrade-git | Jul 30, 2024 | Oct 14, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-githuawei-euleros-2_0_sp2-upgrade-perl-git | Sep 12, 2019 | Oct 14, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-githuawei-euleros-2_0_sp3-upgrade-perl-git | Sep 25, 2019 | Oct 14, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-githuawei-euleros-2_0_sp5-upgrade-perl-git | Sep 12, 2019 | Oct 14, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-developer-versioning-git-2-15-0-0-175-3-28-0-1-0 | Feb 6, 2018 | Oct 14, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 12, 2017 | |
| Suse | — | suse-upgrade-gitsuse-upgrade-git-archsuse-upgrade-git-coresuse-upgrade-git-credential-gnome-keyringsuse-upgrade-git-credential-libsecretsuse-upgrade-git-cvssuse-upgrade-git-daemonsuse-upgrade-git-docsuse-upgrade-git-emailsuse-upgrade-git-guisuse-upgrade-git-p4suse-upgrade-git-svnsuse-upgrade-git-websuse-upgrade-gitk | Apr 11, 2018 | Oct 14, 2017 |
| Ubuntu | ubuntu-upgrade-git | Dec 4, 2018 | Oct 14, 2017 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Aug 25, 2025 | Oct 14, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub