UNIX Hard Link in Git - CVE-2024-32020
Published: June 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise the original repository.
The vulnerability exists due to insecure hardlink following when working with local clones. Local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user.
Affected software
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Amazon Linux AMI
Oracle Linux
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
Slackware Linux
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Development Tools Module
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Solaris
Voice Gateway
Git for Windows
Storage Resource Manager
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Juniper Junos Space
git (Ubuntu package)
swiftlint
git-gui
gitk
git-web
git-core-debuginfo
git-debugsource
git-cvs
git-email
git-daemon-debuginfo
git
git-core
git-daemon
git-svn
perl-Git
perl-Git-SVN
git-help
git-debuginfo
git-doc
git-p4
git-credential-libsecret-debuginfo
git-credential-libsecret
git-arch
git-credential-gnome-keyring
git-credential-gnome-keyring-debuginfo
git (Debian package)
git (Red Hat package)
git-subtree
git-all
git-core-doc
git-instaweb
gitweb
Red Hat OpenShift GitOps
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
Autodesk Infraworks
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2024-32020
Voice Gateway - update to 1.0.8.12
Git for Windows - addressed in versions 2.39.4.1, 2.43.4.1, 2.44.1.1, 2.45.1.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Juniper Junos Space - update to 24.1R3
git (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.25.1-1ubuntu3.12, 1:2.34.1-1ubuntu1.11, 1:2.40.1-1ubuntu1.1, 1:2.43.0-1ubuntu7.1
swiftlint - update to 0.57.1-1.fc42
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.11.6, 1.12.5, 1.13.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.7, 2.9.5, 2.10.4
git-gui - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
gitk - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-web - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debugsource - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-cvs - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-email - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon-debuginfo - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-core - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-daemon - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-svn - addressed in versions 2.26.2-27.78.1, 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-gui - update to 2.27.0-17
gitk - update to 2.27.0-17
perl-Git - update to 2.27.0-17
git-web - update to 2.27.0-17
perl-Git-SVN - update to 2.27.0-17
git-help - update to 2.27.0-17
git-svn - update to 2.27.0-17
git-debuginfo - update to 2.27.0-17
git-daemon - update to 2.27.0-17
git-debugsource - update to 2.27.0-17
git - update to 2.27.0-17
git-email - update to 2.27.0-17
perl-Git - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-doc - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-p4 - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-libsecret-debuginfo - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-libsecret - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-arch - addressed in versions 2.35.3-150300.10.39.1, 2.43.0-150600.3.3.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.39.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.39.1
git - addressed in versions 2.38.4-1.81, 2.40.1-1
git - update to 2.39.4
git (Debian package) - update to 1:2.39.5-0+deb12u1
git (Red Hat package) - addressed in versions 2.43.5-1.el8_10, 2.43.5-1.el9_4
git - update to 2.43.5-1.0.1
git-core - update to 2.43.5-1.0.1
git-credential-libsecret - update to 2.43.5-1.0.1
git-daemon - update to 2.43.5-1.0.1
git-subtree - update to 2.43.5-1.0.1
git-all - update to 2.43.5-1.0.1
git-core-doc - update to 2.43.5-1.0.1
git-email - update to 2.43.5-1.0.1
git-gui - update to 2.43.5-1.0.1
git-instaweb - update to 2.43.5-1.0.1
git-svn - update to 2.43.5-1.0.1
gitk - update to 2.43.5-1.0.1
gitweb - update to 2.43.5-1.0.1
perl-Git - update to 2.43.5-1.0.1
perl-Git-SVN - update to 2.43.5-1.0.1
git - update to 2.45.1-1.fc40
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.13.45, 4.14.32, 4.14.33, 4.16.3, 4.16.15, 4.17.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
OpenShift Logging - addressed in versions 5.6.21, 5.8.9
Oracle Solaris - update to 11.4 SRU 71
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86
External References
Related Security Bulletins
- Multiple vulnerabilities in Git
- Multiple vulnerabilities in Git for Windows
- Ubuntu update for git
- Amazon Linux AMI update for git
- SUSE update for git
- Fedora 40 update for git
- openEuler update for git
- Red Hat Enterprise Linux 9 update for git
- Red Hat Enterprise Linux 8 update for git
- Slackware Linux update for git
- SUSE update for git
- SUSE update for git
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Amazon Linux AMI update for git
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.8
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Debian update for git
- Ubuntu update for git
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Autodesk InfraWorks update for third-party components
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Fedora 42 update for swiftlint
- SUSE update for git
- Anolis OS update for git
- Junos Space update for third-party components
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Voice Gateway