libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2Upgrade eza | Aug 22, 2024 | Feb 6, 2024 |
| Amazon Linux Ami 2 | — | Upgrade rustfmtUpgrade rust-debuginfoUpgrade rust-toolset-srpm-macrosUpgrade rust-debugger-commonUpgrade rust-std-staticUpgrade rust-analysisUpgrade rustUpgrade rust-toolsetUpgrade rust-analyzerUpgrade rust-gdbUpgrade clippyUpgrade rust-srcUpgrade cargoUpgrade rust-doc | Mar 19, 2024 | Feb 6, 2024 |
| Amazon_linux | — | Upgrade rust | Jan 25, 2025 | Feb 6, 2024 |
| Amazon_linux_2023 | — | Upgrade rustfmt-debuginfoUpgrade cargoUpgrade rust-debugger-commonUpgrade rust-debuginfoUpgrade rust-lldbUpgrade rust-analyzerUpgrade rust-std-static-wasm32-unknown-unknownUpgrade libgit2-debugsourceUpgrade rust-analysisUpgrade rust-docUpgrade libgit2Upgrade rust-std-staticUpgrade rust-std-static-wasm32-wasiUpgrade rust-debugsourceUpgrade rust-srcUpgrade clippyUpgrade rust-analyzer-debuginfoUpgrade rustUpgrade clippy-debuginfoUpgrade rust-gdbUpgrade libgit2-debuginfoUpgrade cargo-debuginfoUpgrade libgit2-develUpgrade rustfmt | Feb 17, 2025 | Feb 6, 2024 |
| Debian | — | Upgrade libgit2 | Feb 12, 2024 | Feb 6, 2024 |
| Freebsd | — | Upgrade libgit2Upgrade eza | Feb 9, 2024 | Feb 8, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libgit2 | Jul 23, 2024 | Feb 6, 2024 |
| Suse | — | Upgrade gitkUpgrade git-docUpgrade libgit2-28Upgrade libgit2-24Upgrade git-coreUpgrade git-webUpgrade git-guiUpgrade libgit2-1_7Upgrade git-svnUpgrade libgit2-1_3-32bitUpgrade libgit2-develUpgrade git-archUpgrade perl-gitUpgrade git-emailUpgrade libgit2-1_9Upgrade gitUpgrade git-credential-gnome-keyringUpgrade git-p4Upgrade git-daemonUpgrade git-credential-libsecretUpgrade git-cvsUpgrade libgit2-toolsUpgrade libgit2-1_3Upgrade libgit2-26 | Jul 23, 2024 | Feb 6, 2024 |
| Ubuntu | — | Upgrade libgit2-28Upgrade libgit2-26 (Ubuntu Pro)Upgrade libgit2-24 (Ubuntu Pro)Upgrade libgit2-1.5Upgrade libgit2-1.1 | Mar 6, 2024 | Feb 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub