CVE-2018-15501: Debian Linux
High severity, CVSS 7.5. EPSS: 4.4% chance of exploitation in the next 30 days.
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- LIBGIT2 LIBGIT2: before 0.26.6 (fixed in 0.26.6); from 0.27.0, before 0.27.4 (fixed in 0.27.4)
Published 2018-08-18. Last modified 2026-06-17.