Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11021

Опубликовано: 29 мар. 2026
Источник: fstec
CVSS3: 2.8
CVSS2: 1.7
EPSS Низкий

Описание

Уязвимость библиотеки go-git связана с непроверенным индексированием массива. Эксплуатация уязвимости может позволить нарушителю оказать воздействие на доступность защищаемой информации

Вендор

Red Hat Inc.
ООО «Ред Софт»
GitHub Inc

Наименование ПО

Red Hat Enterprise Linux
OpenShift Container Platform
Openshift Service Mesh
OpenShift Developer Tools and Services
Node HealthCheck Operator
Network Observability Operator
Migration Toolkit for Virtualization
OpenShift Serverless
Migration Toolkit for Containers
OpenShift Pipelines
Logging subsystem for Red Hat OpenShift
Red Hat Advanced Cluster Management for Kubernetes 2
Builds for Red Hat OpenShift
Confidential Compute Attestation
Assisted Installer for Red Hat OpenShift Container Platform
РЕД ОС
Red Hat Enterprise Linux AI
External Secrets Operator for Red Hat OpenShift
Pen Drive Powered by Red Hat Lightspeed
Red Hat OpenShift AI
Machine Deletion Remediation Operator
Power monitoring for Red Hat OpenShift
Kernel Module Management Operator for Red Hat Openshift
go-git

Версия ПО

8 (Red Hat Enterprise Linux)
4 (OpenShift Container Platform)
2 (Openshift Service Mesh)
9 (Red Hat Enterprise Linux)
- (OpenShift Developer Tools and Services)
- (Node HealthCheck Operator)
- (Network Observability Operator)
- (Migration Toolkit for Virtualization)
- (OpenShift Serverless)
- (Migration Toolkit for Containers)
- (OpenShift Pipelines)
- (Logging subsystem for Red Hat OpenShift)
- (Red Hat Advanced Cluster Management for Kubernetes 2)
3 (Openshift Service Mesh)
- (Builds for Red Hat OpenShift)
- (Confidential Compute Attestation)
2 (Assisted Installer for Red Hat OpenShift Container Platform)
8.0 (РЕД ОС)
3 (Red Hat Enterprise Linux AI)
- (External Secrets Operator for Red Hat OpenShift)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat OpenShift AI)
- (Machine Deletion Remediation Operator)
- (Power monitoring for Red Hat OpenShift)
- (Kernel Module Management Operator for Red Hat Openshift)
до 5.17.1 (go-git)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО виртуализации/ПО виртуального программно-аппаратного средства
Сетевое средство

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 8
Red Hat Inc. Red Hat Enterprise Linux 9
ООО «Ред Софт» РЕД ОС 8.0
Red Hat Inc. Red Hat Enterprise Linux AI 3

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 1,7)
Низкий уровень опасности (базовая оценка CVSS 3.1 составляет 2,8)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций:
Для go-git:
https://github.com/go-git/go-git/security/advisories/GHSA-gm2x-2g9h-ccm8
Для Ред ОС:
http://repo.red-soft.ru/redos/8.0/x86_64/updates/
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-33762

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 5%
0.00153
Низкий

2.8 Low

CVSS3

1.7 Low

CVSS2

Связанные уязвимости

CVSS3: 2.8
redos
2 месяца назад

Уязвимость portainer-ce

CVSS3: 2.8
ubuntu
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1.

CVSS3: 2.8
redhat
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1.

CVSS3: 2.8
nvd
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1.

CVSS3: 2.8
debian
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. ...

EPSS

Процентиль: 5%
0.00153
Низкий

2.8 Low

CVSS3

1.7 Low

CVSS2