<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:11:30.740668+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01377</id>
    <title>bdu:2024-01377</title>
    <updated>2026-10-03T16:11:30.759306+00:00</updated>
    <content>bdu:2024-01377</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01377"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-24577</id>
    <title>BELL-CVE-2024-24577</title>
    <updated>2026-10-03T16:11:30.759345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: libgit2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-24577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-ds47827</id>
    <title>CLEANSTART-2024-DS47827 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowin…</title>
    <updated>2026-10-03T16:11:30.759373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: eza</p>
<p>Security vulnerability affects the eza package. libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-ds47827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-239680</id>
    <title>EUVD-2026-239680</title>
    <updated>2026-10-03T16:11:30.759399+00:00</updated>
    <content>EUVD-2026-239680</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-239680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24577</id>
    <title>fkie_cve-2024-24577</title>
    <updated>2026-10-03T16:11:30.759411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-24577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-24577</id>
    <title>gsd-2024-24577</title>
    <updated>2026-10-03T16:11:30.759435+00:00</updated>
    <content>gsd-2024-24577</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-24577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-24577</id>
    <title>msrc_CVE-2024-24577 — libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`</title>
    <updated>2026-10-03T16:11:30.759446+00:00</updated>
    <content>msrc_CVE-2024-24577</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-24577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1188</id>
    <title>OESA-2024-1188 — libgit2 security update</title>
    <updated>2026-10-03T16:11:30.759462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libgit2, openEuler:20.03-LTS-SP4: libgit2, openEuler:22.03-LTS: libgit2, openEuler:22.03-LTS-SP1: libgit2, openEuler:22.03-LTS-SP2: libgit2, openEuler:22.03-LTS-SP3: libgit2</p>
<p>libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language which supports C bindings.

Security Fix(es):

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.(CVE-2024-24577)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1188"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13661-1</id>
    <title>openSUSE-SU-2024:13661-1 — libgit2-1_7-1.7.2-1.1 on GA media</title>
    <updated>2026-10-03T16:11:30.759494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libgit2-1_7-1.7.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13661-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2024-0013</id>
    <title>RUSTSEC-2024-0013 — Memory corruption, denial of service, and arbitrary code execution in libgit2</title>
    <updated>2026-10-03T16:11:30.759512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: libgit2-sys</p>
<p>The [libgit2](https://github.com/libgit2/libgit2/) project fixed three security issues in the 1.7.2 release. These issues are:</p>
<p>* The `git_revparse_single` function can potentially enter an infinite loop on a well-crafted input, potentially causing a Denial of Service. This function is exposed in the `git2` crate via the [`Repository::revparse_single`](https://docs.rs/git2/latest/git2/struct.Repository.html#method.revparse_single) method.
* The `git_index_add` function may cause heap corruption and possibly lead to arbitrary code execution. This function is exposed in the `git2` crate via the [`Index::add`](https://docs.rs/git2/latest/git2/struct.Index.html#method.add) method.
* The smart transport negotiation may experience an out-of-bounds read when a remote server did not advertise capabilities.</p>
<p>The `libgit2-sys` crate bundles libgit2, or optionally links to a system libgit2 library. In either case, versions of the libgit2 library less than 1.7.2 are vulnerable. The 0.16.2 release of `libgit2-sys` bundles the fixed version of 1.7.2, and requires a system libgit2 version of at least 1.7.2.</p>
<p>It is recommended that all users upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2024-0013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2579-1</id>
    <title>SUSE-SU-2024:2579-1 — Security update for git</title>
    <updated>2026-10-03T16:11:30.759539+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for git</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2579-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24577</id>
    <title>UBUNTU-CVE-2024-24577</title>
    <updated>2026-10-03T16:11:30.759555+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: libgit2, Ubuntu:Pro:18.04:LTS: libgit2, Ubuntu:20.04:LTS: libgit2, Ubuntu:22.04:LTS: libgit2</p>
<p>libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0225</id>
    <title>WID-SEC-W-2025-0225 — Dell PowerProtect Data Domain: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:11:30.759580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain ausnutzen, um erhöhte Rechte zu erlangen, einen Denial-of-Service-Zustand herbeizuführen und einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0225"/>
  </entry>
</feed>
