libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2Upgrade eza | Aug 22, 2024 | Feb 6, 2024 |
| Amazon Linux Ami 2 | — | Upgrade rust-toolsetUpgrade clippyUpgrade rust-docUpgrade rust-gdbUpgrade cargoUpgrade rust-srcUpgrade rust-analyzerUpgrade rust-analysisUpgrade rust-std-staticUpgrade rust-debuginfoUpgrade rust-toolset-srpm-macrosUpgrade rustfmtUpgrade rust-debugger-commonUpgrade rust | Mar 19, 2024 | Feb 6, 2024 |
| Amazon_linux | — | Upgrade rust | Jan 25, 2025 | Feb 6, 2024 |
| Amazon_linux_2023 | — | Upgrade rust-debuginfoUpgrade rust-lldbUpgrade cargoUpgrade libgit2-debugsourceUpgrade rust-docUpgrade rustUpgrade rust-std-static-wasm32-wasiUpgrade rustfmt-debuginfoUpgrade rust-std-static-wasm32-unknown-unknownUpgrade rust-debugger-commonUpgrade libgit2Upgrade rust-debugsourceUpgrade clippyUpgrade rust-analyzer-debuginfoUpgrade rust-std-staticUpgrade rust-analysisUpgrade rust-analyzerUpgrade rust-srcUpgrade rustfmtUpgrade cargo-debuginfoUpgrade libgit2-debuginfoUpgrade rust-gdbUpgrade libgit2-develUpgrade clippy-debuginfo | Feb 17, 2025 | Feb 6, 2024 |
| Debian | — | Upgrade libgit2 | Feb 12, 2024 | Feb 6, 2024 |
| Freebsd | — | Upgrade ezaUpgrade libgit2 | Feb 9, 2024 | Feb 8, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libgit2 | Jul 23, 2024 | Feb 6, 2024 |
| Suse | — | Upgrade git-archUpgrade git-daemonUpgrade libgit2-toolsUpgrade perl-gitUpgrade libgit2-26Upgrade git-credential-gnome-keyringUpgrade libgit2-1_3Upgrade gitUpgrade git-p4Upgrade git-credential-libsecretUpgrade git-cvsUpgrade git-emailUpgrade libgit2-1_9Upgrade git-svnUpgrade libgit2-24Upgrade git-webUpgrade git-guiUpgrade libgit2-28Upgrade git-coreUpgrade git-docUpgrade gitkUpgrade libgit2-develUpgrade libgit2-1_3-32bitUpgrade libgit2-1_7 | Jul 23, 2024 | Feb 6, 2024 |
| Ubuntu | — | Upgrade libgit2-1.1Upgrade libgit2-1.5Upgrade libgit2-28Upgrade libgit2-26 (Ubuntu Pro)Upgrade libgit2-24 (Ubuntu Pro) | Mar 6, 2024 | Feb 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub