<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:11:07 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-01377</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01377</link>
      <description>bdu:2024-01377</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01377</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-24577</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-24577</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: libgit2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: libgit2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-24577</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-DS47827 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowin…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-ds47827</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: eza&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the eza package. libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: eza&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the eza package. libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-ds47827</guid>
    </item>
    <item>
      <title>EUVD-2026-239680</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-239680</link>
      <description>EUVD-2026-239680</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-239680</guid>
    </item>
    <item>
      <title>fkie_cve-2024-24577</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24577</link>
      <description>&lt;p&gt;libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-24577</guid>
    </item>
    <item>
      <title>gsd-2024-24577</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-24577</link>
      <description>gsd-2024-24577</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-24577</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-24577 — libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-24577</link>
      <description>msrc_CVE-2024-24577</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-24577</guid>
    </item>
    <item>
      <title>OESA-2024-1188 — libgit2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1188</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libgit2, openEuler:20.03-LTS-SP4: libgit2, openEuler:22.03-LTS: libgit2, openEuler:22.03-LTS-SP1: libgit2, openEuler:22.03-LTS-SP2: libgit2, openEuler:22.03-LTS-SP3: libgit2&lt;/p&gt;
&lt;p&gt;libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language which supports C bindings.&#13;
&#13;
Security Fix(es):&#13;
&#13;
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.(CVE-2024-24577)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libgit2, openEuler:20.03-LTS-SP4: libgit2, openEuler:22.03-LTS: libgit2, openEuler:22.03-LTS-SP1: libgit2, openEuler:22.03-LTS-SP2: libgit2, openEuler:22.03-LTS-SP3: libgit2&lt;/p&gt;
&lt;p&gt;libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language which supports C bindings.&#13;
&#13;
Security Fix(es):&#13;
&#13;
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.(CVE-2024-24577)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1188</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13661-1 — libgit2-1_7-1.7.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13661-1</link>
      <description>&lt;p&gt;libgit2-1_7-1.7.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libgit2-1_7-1.7.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13661-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2024-0013 — Memory corruption, denial of service, and arbitrary code execution in libgit2</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2024-0013</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: libgit2-sys&lt;/p&gt;
&lt;p&gt;The [libgit2](https://github.com/libgit2/libgit2/) project fixed three security issues in the 1.7.2 release. These issues are:&lt;/p&gt;
&lt;p&gt;* The `git_revparse_single` function can potentially enter an infinite loop on a well-crafted input, potentially causing a Denial of Service. This function is exposed in the `git2` crate via the [`Repository::revparse_single`](https://docs.rs/git2/latest/git2/struct.Repository.html#method.revparse_single) method.
* The `git_index_add` function may cause heap corruption and possibly lead to arbitrary code execution. This function is exposed in the `git2` crate via the [`Index::add`](https://docs.rs/git2/latest/git2/struct.Index.html#method.add) method.
* The smart transport negotiation may experience an out-of-bounds read when a remote server did not advertise capabilities.&lt;/p&gt;
&lt;p&gt;The `libgit2-sys` crate bundles libgit2, or optionally links to a system libgit2 library. In either case, versions of the libgit2 library less than 1.7.2 are vulnerable. The 0.16.2 release of `libgit2-sys` bundles the fixed version of 1.7.2, and requires a system libgit2 version of at least 1.7.2.&lt;/p&gt;
&lt;p&gt;It is recommended that all users upgrade.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: libgit2-sys&lt;/p&gt;
&lt;p&gt;The [libgit2](https://github.com/libgit2/libgit2/) project fixed three security issues in the 1.7.2 release. These issues are:&lt;/p&gt;
&lt;p&gt;* The `git_revparse_single` function can potentially enter an infinite loop on a well-crafted input, potentially causing a Denial of Service. This function is exposed in the `git2` crate via the [`Repository::revparse_single`](https://docs.rs/git2/latest/git2/struct.Repository.html#method.revparse_single) method.
* The `git_index_add` function may cause heap corruption and possibly lead to arbitrary code execution. This function is exposed in the `git2` crate via the [`Index::add`](https://docs.rs/git2/latest/git2/struct.Index.html#method.add) method.
* The smart transport negotiation may experience an out-of-bounds read when a remote server did not advertise capabilities.&lt;/p&gt;
&lt;p&gt;The `libgit2-sys` crate bundles libgit2, or optionally links to a system libgit2 library. In either case, versions of the libgit2 library less than 1.7.2 are vulnerable. The 0.16.2 release of `libgit2-sys` bundles the fixed version of 1.7.2, and requires a system libgit2 version of at least 1.7.2.&lt;/p&gt;
&lt;p&gt;It is recommended that all users upgrade.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2024-0013</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2579-1 — Security update for git</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2579-1</link>
      <description>&lt;p&gt;Security update for git&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for git&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2579-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-24577</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24577</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libgit2, Ubuntu:Pro:18.04:LTS: libgit2, Ubuntu:20.04:LTS: libgit2, Ubuntu:22.04:LTS: libgit2&lt;/p&gt;
&lt;p&gt;libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: libgit2, Ubuntu:Pro:18.04:LTS: libgit2, Ubuntu:20.04:LTS: libgit2, Ubuntu:22.04:LTS: libgit2&lt;/p&gt;
&lt;p&gt;libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24577</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0225 — Dell PowerProtect Data Domain: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0225</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain ausnutzen, um erhöhte Rechte zu erlangen, einen Denial-of-Service-Zustand herbeizuführen und einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain ausnutzen, um erhöhte Rechte zu erlangen, einen Denial-of-Service-Zustand herbeizuführen und einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0225</guid>
    </item>
  </channel>
</rss>
