Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 38: 2024-a7a3c8ccdd Critical Heap Corruption in libgit2

fedora
Calendar Grey February 17, 2024
Dist Fedora Esm H88
Important update for libgit2 on Fedora 38 fixes memory management issues like heap corruption, boosting performance and reliability of git operations
Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Summary

libgit2 is a portable, pure C implementation of the Git core methods

provided as a re-entrant linkable library with a solid API, allowing

you to write native speed custom Git applications in any language

with bindings.

Update Information:

Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Change Log

* Thu Feb 8 2024 Pete Walter - 1.6.5-1 - Update to 1.6.5

References


[ 1 ] Bug #2263096 - TRIAGE CVE-2024-24577 libgit2: arbitrary code execution due to heap corruption in git_index_add [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263096 [ 2 ] Bug #2263101 - TRIAGE CVE-2024-24575 libgit2: potential infiniate loop condition in git_revparse_single [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263101

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a7a3c8ccdd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libgit2
Product: Fedora 38
Version: 1.6.5
Release: 1.fc38
Summary: C implementation of the Git core methods as a library with a solid API

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here