Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11028

Опубликовано: 29 мар. 2026
Источник: fstec
CVSS3: 5
CVSS2: 4.6
EPSS Низкий

Описание

Уязвимость библиотеки go-git связана с целочисленной потерей значимости. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании с помощью специально созданного вредоносного .idx файла

Вендор

Red Hat, Inc.
ООО «Ред Софт»
GitHub Inc

Наименование ПО

Red Hat Enterprise Linux
OpenShift Container Platform
Openshift Service Mesh
Red Hat OpenShift GitOps
OpenShift Developer Tools and Services
Migration Toolkit for Virtualization
OpenShift Serverless
Migration Toolkit for Containers
OpenShift Pipelines
Red Hat Advanced Cluster Security
Logging subsystem for Red Hat OpenShift
Red Hat Advanced Cluster Management for Kubernetes 2
Red Hat AI Inference Server
Builds for Red Hat OpenShift
Confidential Compute Attestation
Assisted Installer for Red Hat OpenShift Container Platform
РЕД ОС
Red Hat Enterprise Linux AI
External Secrets Operator for Red Hat OpenShift
Pen Drive Powered by Red Hat Lightspeed
Red Hat OpenShift AI
Machine Deletion Remediation Operator
Red Hat Edge Manager
Kernel Module Management Operator for Red Hat Openshift
go-git

Версия ПО

8 (Red Hat Enterprise Linux)
4 (OpenShift Container Platform)
2 (Openshift Service Mesh)
- (Red Hat OpenShift GitOps)
9 (Red Hat Enterprise Linux)
- (OpenShift Developer Tools and Services)
- (Migration Toolkit for Virtualization)
- (OpenShift Serverless)
- (Migration Toolkit for Containers)
- (OpenShift Pipelines)
4 (Red Hat Advanced Cluster Security)
- (Logging subsystem for Red Hat OpenShift)
- (Red Hat Advanced Cluster Management for Kubernetes 2)
- (Red Hat AI Inference Server)
3 (Openshift Service Mesh)
- (Builds for Red Hat OpenShift)
- (Confidential Compute Attestation)
2 (Assisted Installer for Red Hat OpenShift Container Platform)
8.0 (РЕД ОС)
3 (Red Hat Enterprise Linux AI)
- (External Secrets Operator for Red Hat OpenShift)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat OpenShift AI)
- (Machine Deletion Remediation Operator)
1 (Red Hat Edge Manager)
- (Kernel Module Management Operator for Red Hat Openshift)
от 5.0.0 до 5.17.1 (go-git)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО виртуализации/ПО виртуального программно-аппаратного средства
Сетевое средство

Операционные системы и аппаратные платформы

Red Hat, Inc. Red Hat Enterprise Linux 8
Red Hat, Inc. Red Hat Enterprise Linux 9
ООО «Ред Софт» РЕД ОС 8.0
Red Hat, Inc. Red Hat Enterprise Linux AI 3

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,6)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций:
Для go-git:
https://github.com/go-git/go-git/security/advisories/GHSA-jhf3-xxhw-2wpp
Для Ред ОС:
http://repo.red-soft.ru/redos/8.0/x86_64/updates/
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-34165

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 4%
0.00147
Низкий

5 Medium

CVSS3

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 5
redos
2 месяца назад

Уязвимость portainer-ce

CVSS3: 5
ubuntu
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.

CVSS3: 5
redhat
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.

CVSS3: 5
nvd
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.

CVSS3: 5
debian
6 месяцев назад

go-git is an extensible git implementation library written in pure Go. ...

EPSS

Процентиль: 4%
0.00147
Низкий

5 Medium

CVSS3

4.6 Medium

CVSS2