CVE-2016-10129: Null Pointer Dereference
Last updated 13 August 2026
Other sources
The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cargoto a version that resolves this vulnerability.Fixed in 0.47.0-3Fixed in 0.66.0+ds1-1 - Upgrade
Upgrade
debian/libgit2to a version that resolves this vulnerability.Fixed in 1.1.0+dfsg.1-4+deb11u2Fixed in 1.5.1+ds-1+deb12u1Fixed in 1.9.0+ds-2Fixed in 1.9.6+ds-1 - Upgrade
Upgrade
libgit2to a version that resolves this vulnerability.Fixed in 0.24.6 - Upgrade
Upgrade
libgit2to a version that resolves this vulnerability.Fixed in 0.25.1
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10129?
CVE-2016-10129 is classified as a denial of service vulnerability due to a NULL pointer dereference.
How do I fix CVE-2016-10129?
To fix CVE-2016-10129, update libgit2 to version 0.24.6 or 0.25.1 or later.
What versions of libgit2 are affected by CVE-2016-10129?
CVE-2016-10129 affects libgit2 versions before 0.24.6 and specifically 0.25.0 and its release candidates.
What can exploit CVE-2016-10129?
Remote attackers can exploit CVE-2016-10129 by sending an empty packet line to the Git Smart Protocol.
Is CVE-2016-10129 a critical vulnerability?
While CVE-2016-10129 leads to a denial of service, its criticality depends on the context and potential impact on services relying on libgit2.