CVE-2024-32004: Debian Linux

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Fedoraproject Fedora: version 40 only
  • Git-Scm Git: before 2.39.4 (fixed in 2.39.4); from 2.40.0, before 2.40.2 (fixed in 2.40.2); from 2.42.0, before 2.42.2 (fixed in 2.42.2); from 2.43.0, before 2.43.4 (fixed in 2.43.4); version 2.41.0 only; version 2.44.0 only; …

Published 2024-05-14. Last modified 2026-06-17.