PT-2026-83106 · Gitoxide · Gitoxide
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
gitoxide versions prior to 0.69.0
Description
The issue involves unchecked array indexing during delta application and uncapped memory allocation triggered by attacker-controlled size headers in the
gix-pack module. An attacker can send specially crafted pack data during clone or fetch operations to cause the process to panic or be killed due to out-of-memory conditions.Recommendations
Update to version 0.69.0 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitoxide