CVE-2018-8099: Double Free
Incorrect returning of an error code in the index.c:readentry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libgit2to a version that resolves this vulnerability.Fixed in 1.1.0+dfsg.1-4+deb11u2Fixed in 1.5.1+ds-1+deb12u1Fixed in 1.9.0+ds-2Fixed in 1.9.6+ds-1 - Upgrade
Upgrade
libgit2to a version that resolves this vulnerability.Fixed in 0.26.2
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-8099.
What is the title of the vulnerability?
The title of the vulnerability is "Incorrect returning of an error code in the index.c:read_entry() function leads to a double free."
What is the impact of this vulnerability?
The vulnerability can cause a denial of service.
What is the affected software?
The affected software is Libgit2 (version up to exclusive 0.26.2) and Debian Linux (version 9.0).
What is the severity of this vulnerability?
The severity of this vulnerability is medium (CVSS score of 6.5).
How can I fix this vulnerability?
To fix this vulnerability, update Libgit2 to version 0.26.2 or later and Debian Linux to a version higher than 9.0.