<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:25:29 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-35197 — gix refs and paths with reserved Windows device names access the devices</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-35197</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Byron gitoxide&lt;/p&gt;
&lt;p&gt;gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary message that appear to have come from the application, and potentially other harmful effects under limited circumstances. If Windows is not used, or untrusted repositories are not cloned or otherwise used, then there is no impact. A minor degradation in availability may also be possible, such as with a very large file named `CON`, though the user could interrupt the application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Byron gitoxide&lt;/p&gt;
&lt;p&gt;gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary message that appear to have come from the application, and potentially other harmful effects under limited circumstances. If Windows is not used, or untrusted repositories are not cloned or otherwise used, then there is no impact. A minor degradation in availability may also be possible, such as with a very large file named `CON`, though the user could interrupt the application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-35197</guid>
    </item>
    <item>
      <title>GHSA-49jc-r788-3fc9 — gix refs and paths with reserved Windows device names access the devices</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-49jc-r788-3fc9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: gix-worktree-state, crates.io: gitoxide, crates.io: gix-worktree, crates.io: gitoxide-core, crates.io: gix, crates.io: gix-ref, crates.io: gix-index&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary message that appear to have come from the application, and potentially other harmful effects under limited circumstances.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;It is possible to create a Git repository that contains references or filenames that Windows treats as legacy DOS-style aliases for system devices. When such a repository is cloned:&lt;/p&gt;
&lt;p&gt;- In references, `gix-ref` does not include a check for such names before attempting to access them on disk, which reads from the devices, though the ability to exfiltrate data appears limited.
- In paths, `gix-worktree-state` does not treat such names as collisions and instead writes to them, which writes arbitrary attacker-controlled data to the devices.&lt;/p&gt;
&lt;p&gt;Some such device names refer to devices that are often absent or inaccessible. But a few are guaranteed to be available, allowing some attacks to be carried out with low complexity. For both reading refs and writing paths, one important case is the console:&lt;/p&gt;
&lt;p&gt;- Reading a ref whose last component (e.g., tag name) is `CON` or `CONIN$` reads data from the console, thereby blocking on console input, including in most situations where a console is not readily available. This may facilitate denial of service attacks.
- Checking out a f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: gix-worktree-state, crates.io: gitoxide, crates.io: gix-worktree, crates.io: gitoxide-core, crates.io: gix, crates.io: gix-ref, crates.io: gix-index&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when cloned, to cause indefinite blocking or the production of arbitrary message that appear to have come from the application, and potentially other harmful effects under limited circumstances.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;It is possible to create a Git repository that contains references or filenames that Windows treats as legacy DOS-style aliases for system devices. When such a repository is cloned:&lt;/p&gt;
&lt;p&gt;- In references, `gix-ref` does not include a check for such names before attempting to access them on disk, which reads from the devices, though the ability to exfiltrate data appears limited.
- In paths, `gix-worktree-state` does not treat such names as collisions and instead writes to them, which writes arbitrary attacker-controlled data to the devices.&lt;/p&gt;
&lt;p&gt;Some such device names refer to devices that are often absent or inaccessible. But a few are guaranteed to be available, allowing some attacks to be carried out with low complexity. For both reading refs and writing paths, one important case is the console:&lt;/p&gt;
&lt;p&gt;- Reading a ref whose last component (e.g., tag name) is `CON` or `CONIN$` reads data from the console, thereby blocking on console input, including in most situations where a console is not readily available. This may facilitate denial of service attacks.
- Checking out a f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-49jc-r788-3fc9</guid>
    </item>
  </channel>
</rss>
