GHSA-3qx3-6hxr-j2ch

    Dashboard / Vulnerabilities / GHSA-3qx3-6hxr-j2ch

    GHSA-3qx3-6hxr-j2ch

    Published: 8 Feb 2024Last Modified: 13 Mar 2026

    Summary: eza Potential Heap Overflow Vulnerability for AArch64

    Details: ### Summary In `eza`, there exists a potential heap overflow vulnerability, first seen when using Ubuntu for Raspberry Pi series system, on `ubuntu-raspi` kernel, relating to the `.git` directory. ### Details The vulnerability seems to be triggered by the `.git` directory in some projects. This issue may be related to specific files, and the directory structure also plays a role in triggering the vulnerability. Files/folders that may be involved in triggering the vulnerability include `.git/HEAD`, `.git/refs`, and `.git/objects`. As @polly pointed out to me, this is likely caused by [GHSA-j2v7-4f6v-gpg8](https://github.com/libgit2/libgit2/security/advisories/GHSA-j2v7-4f6v-gpg8), which we do seem to use currently. ### PoC For more information check @CuB3y0nd's blogpost [blog](https://www.cubeyond.net/blog/eza-cve-report). ### Impact Arbitrary code execution.

    Affected packages

    Package

    Name: eza

    Purl: pkg:cargo/eza

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.18.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3qx3-6hxr-j2ch | CVE-DB