Bug 1219660 (CVE-2024-24577) - VUL-0: CVE-2024-24577: git,libgit2: arbitrary code execution due to heap corruption in git_index_add
Summary: VUL-0: CVE-2024-24577: git,libgit2: arbitrary code execution due to heap corr...
Status: RESOLVED FIXED
Alias: CVE-2024-24577
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/393299/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-24577:8.6:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-07 08:43 UTC by SMASH SMASH
Modified: 2025-10-15 12:51 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
camila.matos: needinfo? (antonio.teixeira)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-02-07 08:43:06 UTC
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in the `has_dir_name` function in `src/libgit2/index.c`, which frees an entry that should not be freed. The freed entry is later used and overwritten with potentially bad actor-controlled data leading to controlled heap corruption. Depending on the application that uses libgit2, this could lead to arbitrary code execution. This issue has been patched in version 1.6.5 and 1.7.2.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-24577
https://github.com/libgit2/libgit2/releases/tag/v1.6.5
https://github.com/libgit2/libgit2/releases/tag/v1.7.2
https://www.cve.org/CVERecord?id=CVE-2024-24577
https://github.com/libgit2/libgit2/security/advisories/GHSA-j2v7-4f6v-gpg8
https://bugzilla.redhat.com/show_bug.cgi?id=2263095
Comment 2 Andreas Stieger 2024-02-07 19:59:47 UTC
https://build.opensuse.org/request/show/1144998
Comment 3 Marcus Meissner 2024-05-19 18:53:37 UTC
libgit2 affected everywhere.

git has it in read-cache.c, and it looks similar affected in 2.25.2 in SLE12.
also 2.43.0 still looks affected in SLE15 SP6.
Comment 10 Andreas Stieger 2024-07-12 14:33:10 UTC
camila.matos@suse.com set the needinfo flag on me, and I assume this was done in combination with a comment marked private. (There are 5 private comments before bug 1219664 comment #3) If you wish to engage with a volunteer community member, feel free to do so with public comments. If this is for anything other than openSUSE, through, please contact the SUSE bug assignee or the SUSE Product Security team.
Comment 11 Camila Camargo de Matos 2024-07-12 16:12:41 UTC
(In reply to Andreas Stieger from comment #10)
> camila.matos@suse.com set the needinfo flag on me, and I assume this was
> done in combination with a comment marked private. (There are 5 private
> comments before bug 1219664 comment #3) If you wish to engage with a
> volunteer community member, feel free to do so with public comments. If this
> is for anything other than openSUSE, through, please contact the SUSE bug
> assignee or the SUSE Product Security team.

My apologies, it was my mistake. There is no need to worry about the original needinfo request, as I have already adjusted it. Thanks for the answer!
Comment 12 Scott Reeves 2024-07-15 23:38:12 UTC
Scott B. - can you take this one for the libgit2 update. For SLE-15-SP6 the update to 1.7.2 needed for 1219664 will cover this. For the other products a backport will likely be necessary.
Comment 17 Maintenance Automation 2024-07-22 16:30:01 UTC
SUSE-SU-2024:2592-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242592-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34828](https://smelt.suse.de/incident/34828/)
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src):
 git-2.26.2-27.75.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src):
 git-2.26.2-27.75.1
SUSE Linux Enterprise Server 12 SP5 (src):
 git-2.26.2-27.75.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src):
 git-2.26.2-27.75.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Maintenance Automation 2024-07-22 16:36:24 UTC
SUSE-SU-2024:2584-1: An update that solves two vulnerabilities can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242584-1
Category: security (important)
Bug References: 1219660, 1219664
CVE References: CVE-2024-24575, CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34823](https://smelt.suse.de/incident/34823/)
Sources used:
openSUSE Leap 15.6 (src):
 libgit2-1.7.2-150600.3.3.1
Development Tools Module 15-SP6 (src):
 libgit2-1.7.2-150600.3.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 19 Maintenance Automation 2024-07-22 16:36:26 UTC
SUSE-SU-2024:2583-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242583-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34827](https://smelt.suse.de/incident/34827/)
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src):
 libgit2-0.24.1-11.5.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 Maintenance Automation 2024-07-22 20:30:11 UTC
SUSE-SU-2024:2579-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242579-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34831](https://smelt.suse.de/incident/34831/)
Sources used:
Development Tools Module 15-SP6 (src):
 git-2.43.0-150600.3.6.1
openSUSE Leap 15.6 (src):
 git-2.43.0-150600.3.6.1
Basesystem Module 15-SP6 (src):
 git-2.43.0-150600.3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 21 Maintenance Automation 2024-07-23 08:30:22 UTC
SUSE-SU-2024:2599-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242599-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34829](https://smelt.suse.de/incident/34829/)
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src):
 git-2.26.2-150000.59.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src):
 git-2.26.2-150000.59.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src):
 git-2.26.2-150000.59.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 22 Maintenance Automation 2024-07-23 08:30:24 UTC
SUSE-SU-2024:2598-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242598-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34826](https://smelt.suse.de/incident/34826/)
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src):
 libgit2-0.26.8-150000.3.21.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src):
 libgit2-0.26.8-150000.3.21.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src):
 libgit2-0.26.8-150000.3.21.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Maintenance Automation 2024-07-29 08:30:01 UTC
SUSE-SU-2024:2610-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242610-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34825](https://smelt.suse.de/incident/34825/)
Sources used:
SUSE Manager Server 4.3 Module 4.3 (src):
 libgit2-0.28.4-150200.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src):
 libgit2-0.28.4-150200.3.9.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src):
 libgit2-0.28.4-150200.3.9.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src):
 libgit2-0.28.4-150200.3.9.1
SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src):
 libgit2-0.28.4-150200.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src):
 libgit2-0.28.4-150200.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src):
 libgit2-0.28.4-150200.3.9.1
SUSE Enterprise Storage 7.1 (src):
 libgit2-0.28.4-150200.3.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 24 Maintenance Automation 2024-07-30 08:37:28 UTC
SUSE-SU-2024:2619-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242619-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34824](https://smelt.suse.de/incident/34824/)
Sources used:
openSUSE Leap 15.4 (src):
 libgit2-1.3.0-150400.3.9.1
openSUSE Leap 15.5 (src):
 libgit2-1.3.0-150400.3.9.1
Development Tools Module 15-SP5 (src):
 libgit2-1.3.0-150400.3.9.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src):
 libgit2-1.3.0-150400.3.9.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src):
 libgit2-1.3.0-150400.3.9.1
SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (src):
 libgit2-1.3.0-150400.3.9.1
SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src):
 libgit2-1.3.0-150400.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src):
 libgit2-1.3.0-150400.3.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 25 Maintenance Automation 2024-07-30 16:30:47 UTC
SUSE-SU-2024:2656-1: An update that solves one vulnerability can now be installed.

URL: https://www.suse.com/support/update/announcement/2024/suse-su-20242656-1
Category: security (important)
Bug References: 1219660
CVE References: CVE-2024-24577
Maintenance Incident: [SUSE:Maintenance:34830](https://smelt.suse.de/incident/34830/)
Sources used:
openSUSE Leap 15.3 (src):
 git-2.35.3-150300.10.42.1
openSUSE Leap Micro 5.5 (src):
 git-2.35.3-150300.10.42.1
openSUSE Leap 15.5 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise Micro 5.5 (src):
 git-2.35.3-150300.10.42.1
Basesystem Module 15-SP5 (src):
 git-2.35.3-150300.10.42.1
Development Tools Module 15-SP5 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src):
 git-2.35.3-150300.10.42.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src):
 git-2.35.3-150300.10.42.1
SUSE Manager Proxy 4.3 (src):
 git-2.35.3-150300.10.42.1
SUSE Manager Retail Branch Server 4.3 (src):
 git-2.35.3-150300.10.42.1
SUSE Manager Server 4.3 (src):
 git-2.35.3-150300.10.42.1
SUSE Enterprise Storage 7.1 (src):
 git-2.35.3-150300.10.42.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 27 Scott Bradnick 2024-11-11 15:09:44 UTC
Setting to "IN_PROGRESS" but can potentially be closed soon.
Comment 31 Maintenance Automation 2025-09-26 16:40:23 UTC
SUSE-SU-2025:20721-1: An update that solves 10 vulnerabilities and has one fix can now be installed.

URL: https://www.suse.com/support/update/announcement/2025/suse-su-202520721-1
Category: security (critical)
Bug References: 1212476, 1219660, 1235600, 1235601, 1239989, 1245938, 1245939, 1245942, 1245943, 1245946, 1245947
CVE References: CVE-2024-24577, CVE-2024-50349, CVE-2024-52006, CVE-2025-27613, CVE-2025-27614, CVE-2025-46334, CVE-2025-46835, CVE-2025-48384, CVE-2025-48385, CVE-2025-48386
Sources used:
SUSE Linux Micro 6.0 (src):
 git-2.51.0-1.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.