When using an SSH remote with the optional libssh2 backend, libgit2 does
not perform certificate checking by default. (CVE-2023-22742)
Using well-crafted inputs to `git_index_add` can cause heap corruption
that could be leveraged for arbitrary code execution. (CVE-2024-24577)
- https://bugs.mageia.org/show_bug.cgi?id=30633
- https://lists.debian.org/debian-lts-announce/2023/02/msg00034.html
- https://github.com/libgit2/libgit2/security/advisories/GHSA-8643-3wh5-rmjq
- https://lists.suse.com/pipermail/sle-security-updates/2023-March/014158.html
- https://lists.debian.org/debian-lts-announce/2024/02/msg00012.html
- https://www.cve.org/CVERecord?id=CVE-2023-22742
- https://www.cve.org/CVERecord?id=CVE-2024-24577
- 9/core/libgit2-1.3.2-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.