{"id":"GHSA-3qx3-6hxr-j2ch","summary":"eza Potential Heap Overflow Vulnerability for AArch64","details":"### Summary\nIn `eza`, there exists a potential heap overflow vulnerability, first seen when using Ubuntu for Raspberry Pi series system, on `ubuntu-raspi` kernel, relating to the `.git` directory.\n\n### Details\nThe vulnerability seems to be triggered by the `.git` directory in some projects. This issue may be related to specific files, and the directory structure also plays a role in triggering the vulnerability. Files/folders that may be involved in triggering the vulnerability include `.git/HEAD`, `.git/refs`, and `.git/objects`.\n\nAs @polly pointed out to me, this is likely caused by [GHSA-j2v7-4f6v-gpg8](https://github.com/libgit2/libgit2/security/advisories/GHSA-j2v7-4f6v-gpg8), which we do seem to use currently.\n\n### PoC\nFor more information check @CuB3y0nd's blogpost [blog](https://www.cubeyond.net/blog/eza-cve-report).\n\n### Impact\nArbitrary code execution.","aliases":["CVE-2024-25817"],"modified":"2026-03-13T08:00:26.840575Z","published":"2024-02-08T18:47:28Z","related":["CVE-2024-25817"],"database_specific":{"github_reviewed_at":"2024-02-08T18:47:28Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/eza-community/eza/security/advisories/GHSA-3qx3-6hxr-j2ch"},{"type":"WEB","url":"https://github.com/eza-community/eza/commit/47c9b90368c49117ba42760bd58acafa3362cbd4"},{"type":"PACKAGE","url":"https://github.com/eza-community/eza"}],"affected":[{"package":{"name":"eza","ecosystem":"crates.io","purl":"pkg:cargo/eza"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.18.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-3qx3-6hxr-j2ch/GHSA-3qx3-6hxr-j2ch.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}