CVE-2024-24577 is a critical heap corruption vulnerability in libgit2, a C library for Git core methods, affecting versions prior to 1.6.5 and 1.7.2. Maliciously crafted inputs to the git_index_add function can lead to controlled heap corruption due to an improper free operation in the has_dir_name function. This flaw carries a CVSS score of 9.8 (CRITICAL) and could enable arbitrary code execution, with a network attack vector and low attack complexity. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected libgit2 versions should prioritize patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.5CPE matchmatch criteria | cpe:2.3:a:libgit2:libgit2:*:*:*:*:*:*:*:* | ||
>= 1.7.0, < 1.7.2CPE matchmatch criteria | cpe:2.3:a:libgit2:libgit2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.