PT-2024-3834 · Git+10 · Git+10

Pks-T

·

Published

2024-05-14

·

Updated

2026-01-06

·

CVE-2024-32020

CVSS v3.1

3.9

Low

VectorAV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Git versions prior to 2.45.1 Git versions prior to 2.44.1 Git versions prior to 2.43.4 Git versions prior to 2.42.2 Git versions prior to 2.41.1 Git versions prior to 2.40.2 Git versions prior to 2.39.4
Description The issue is related to local clones of Git repositories. When the source and target repositories are on the same disk and owned by different users, Git may create hardlinks to files in the target repository's object database. These hardlinked files can be rewritten by the untrusted user at any point in time. This can lead to unauthorized access and modification of files in the target repository.
Recommendations For versions prior to 2.45.1, update to version 2.45.1 or later. For versions prior to 2.44.1, update to version 2.44.1 or later. For versions prior to 2.43.4, update to version 2.43.4 or later. For versions prior to 2.42.2, update to version 2.42.2 or later. For versions prior to 2.41.1, update to version 2.41.1 or later. For versions prior to 2.40.2, update to version 2.40.2 or later. For versions prior to 2.39.4, update to version 2.39.4 or later.

Exploit

Fix

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4083
ALSA-2024:4084
AZL-42037
AZL-43033
BDU:2024-04214
BIT-GIT-2024-32020
CESA-2024_4084
CVE-2024-32020
DSA-5769-1
GHSA-5RFH-556J-FHGJ
INFSA-2024_4083
INFSA-2024_4084
MGASA-2024-0204
OESA-2024-1662
OPENSUSE-SU-2024:13968-1
OPENSUSE-SU-2024_1807-1
OPENSUSE-SU-2024_2277-1
RHSA-2024:4083
RHSA-2024:4084
RHSA-2024:4368
RHSA-2024_4083
RHSA-2024_4084
RLSA-2024:4083
RLSA-2024:4084
SUSE-SU-2024:1807-1
SUSE-SU-2024:1807-2
SUSE-SU-2024:1854-1
SUSE-SU-2024:2277-1
SUSE-SU-2025:0197-1
SUSE-SU-2025:20049-1
SUSE-SU-2025_0197-1
USN-6793-1
USN-7023-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Git
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu