← Vulnerability feed

Vulnerability record · CVE-2024-24577 · published 6 February 2024

CVE-2024-24577: Libgit2 heap-based buffer overflow vulnerability

Libgit2 · Libgit2

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.

9.8 CVSS 3.1 Critical EPSS 1.5% · top 26.0% CWE-122 · Heap-based buffer overflowCWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/libgit2/libgit2/releases/tag/v1.6.5 Release Notes
https://github.com/libgit2/libgit2/releases/tag/v1.7.2 Release Notes
https://github.com/libgit2/libgit2/security/advisories/GHSA-j2v7-4f6v-gpg8 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/02/msg00012.html
https://lists.fedoraproject.org/archives/list/[email protected]/message/4M3P7WIEPXNRLBINQRJFXUSTN
https://lists.fedoraproject.org/archives/list/[email protected]/message/7CNDW3PF6NHO7OXNM5GN6WSSG
https://lists.fedoraproject.org/archives/list/[email protected]/message/S635BGHHZUMRPI7QOXOJ45QHD
https://lists.fedoraproject.org/archives/list/[email protected]/message/Z6MXOX7I43OWNN7R6M54XLG6U
https://lists.fedoraproject.org/archives/list/[email protected]/message/ZGNHOEE2RBLH7KCJUPUNYG4CD
https://github.com/libgit2/libgit2/releases/tag/v1.6.5 Release Notes
https://github.com/libgit2/libgit2/releases/tag/v1.7.2 Release Notes
https://github.com/libgit2/libgit2/security/advisories/GHSA-j2v7-4f6v-gpg8 Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/02/msg00012.html
https://lists.fedoraproject.org/archives/list/[email protected]/message/4M3P7WIEPXNRLBINQRJFXUSTN
https://lists.fedoraproject.org/archives/list/[email protected]/message/7CNDW3PF6NHO7OXNM5GN6WSSG
https://lists.fedoraproject.org/archives/list/[email protected]/message/S635BGHHZUMRPI7QOXOJ45QHD
https://lists.fedoraproject.org/archives/list/[email protected]/message/Z6MXOX7I43OWNN7R6M54XLG6U
https://lists.fedoraproject.org/archives/list/[email protected]/message/ZGNHOEE2RBLH7KCJUPUNYG4CD

Track CVE-2024-24577 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-12278Libgit2 vulnerabilityAn issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate …EPSS 5.2%9.8CVE-2020-12279Libgit2 vulnerabilityAn issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short …EPSS 5.2%9.8CVE-2014-9390Git clients execute commands via crafted .git/config on case-insensitive filesystemsGit, Mercurial, libgit2, JGit, EGit and Xcode mishandle crafted .git/config paths on Windows and OS X, allowing a remote repository to place a file t…EPSS 76%analysed8.1CVE-2018-10887Libgit2 out-of-bounds read vulnerabilityA flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c fi…EPSS 2.1%7.5CVE-2024-24575Libgit2 uncontrolled resource consumption vulnerabilitylibgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…EPSS 1.4%7.5CVE-2018-15501Debian linux out-of-bounds read vulnerabilityIn ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packe…EPSS 4.4%6.5CVE-2018-10888Libgit2 improper input validation vulnerabilityA flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read whil…EPSS 1.8%6.5CVE-2018-8098Libgit2 integer overflow vulnerabilityInteger overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2024-24577), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.