Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-53587

около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-53587

около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-53587

около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-53587

около 1 месяца назад

libgit2 is a portable C implementation of the Git core methods provide ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:67286

6 дней назад

Important: rust security update

EPSS: Низкий
rocky логотип

RLSA-2026:67285

6 дней назад

Important: rust security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-67286-0

8 дней назад

ELSA-2026-67286-0: rust security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-67285-0

8 дней назад

ELSA-2026-67285-0: rust security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-12652

2 месяца назад

Уязвимость функции set_data() файла src/libgit2/transports/smart_pkt.c реализации методов Git на языке C Libgit2, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-53587

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-53587

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-53587

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-53587

libgit2 is a portable C implementation of the Git core methods provide ...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:67286

Important: rust security update

0%
Низкий
6 дней назад
rocky логотип
RLSA-2026:67285

Important: rust security update

0%
Низкий
6 дней назад
oracle-oval логотип
ELSA-2026-67286-0

ELSA-2026-67286-0: rust security update (IMPORTANT)

0%
Низкий
8 дней назад
oracle-oval логотип
ELSA-2026-67285-0

ELSA-2026-67285-0: rust security update (IMPORTANT)

0%
Низкий
8 дней назад
fstec логотип
BDU:2026-12652

Уязвимость функции set_data() файла src/libgit2/transports/smart_pkt.c реализации методов Git на языке C Libgit2, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу