Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
Published May 14, 2024
9.1
CRITICALCVSS 3.1
EPSS 29.23%
Description
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.
Affected products
-
- Version < 2.39.4StatusaffectedConstraints-
- Version = 2.41.0StatusaffectedConstraints-
- Version = 2.44.0StatusaffectedConstraints-
- Version = 2.45.0StatusaffectedConstraints-
- Version >= 2.40.0, < 2.40.2StatusaffectedConstraints-
- Version >= 2.42.0, < 2.42.2StatusaffectedConstraints-
- Version >= 2.43.0, < 2.43.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
-
- Version 0StatusaffectedConstraints<2.39.4
- Version 2.40.0StatusaffectedConstraints<2.40.2
- Version 2.41.0StatusaffectedConstraints-
- Version 2.42.0StatusaffectedConstraints<2.42.2
- Version 2.43StatusaffectedConstraints<2.43.4
- Version 2.44.0StatusaffectedConstraints-
- Version 2.45.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Red Hat Enterprise Linux 8
git-0:2.43.5-1.el8_10
Fixed · RHSA-2024:4084
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
git-0:2.27.0-5.el8_4
Fixed · RHSA-2024:6028
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
git-0:2.27.0-5.el8_4
Fixed · RHSA-2024:6028
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
git-0:2.27.0-5.el8_4
Fixed · RHSA-2024:6028
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
git-0:2.31.8-3.el8_6
Fixed · RHSA-2024:6027
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
git-0:2.31.8-3.el8_6
Fixed · RHSA-2024:6027
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
git-0:2.31.8-3.el8_6
Fixed · RHSA-2024:6027
Red Hat Enterprise Linux 8.8 Extended Update Support
git-0:2.39.5-1.el8_8
Fixed · RHSA-2024:4579
Red Hat Enterprise Linux 9
git-0:2.43.5-1.el9_4
Fixed · RHSA-2024:4083
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
git-0:2.31.1-6.el9_0
Fixed · RHSA-2024:6610
Red Hat Enterprise Linux 9.2 Extended Update Support
git-0:2.39.5-1.el9_2
Fixed · RHSA-2024:4368
Red Hat Enterprise Linux 10
git
Not affected
Red Hat Enterprise Linux 6
git
Out of support scope
Red Hat Enterprise Linux 7
git
Will not fix
Red Hat Fuse 7
git
Will not fix
Red Hat Software Collections
rh-git227-git
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | git-0:2.43.5-1.el8_10 | Fixed | RHSA-2024:4084 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | git-0:2.27.0-5.el8_4 | Fixed | RHSA-2024:6028 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | git-0:2.27.0-5.el8_4 | Fixed | RHSA-2024:6028 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | git-0:2.27.0-5.el8_4 | Fixed | RHSA-2024:6028 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | git-0:2.31.8-3.el8_6 | Fixed | RHSA-2024:6027 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | git-0:2.31.8-3.el8_6 | Fixed | RHSA-2024:6027 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | git-0:2.31.8-3.el8_6 | Fixed | RHSA-2024:6027 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | git-0:2.39.5-1.el8_8 | Fixed | RHSA-2024:4579 |
| Red Hat Enterprise Linux 9 | git-0:2.43.5-1.el9_4 | Fixed | RHSA-2024:4083 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | git-0:2.31.1-6.el9_0 | Fixed | RHSA-2024:6610 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | git-0:2.39.5-1.el9_2 | Fixed | RHSA-2024:4368 |
| Red Hat Enterprise Linux 10 | git | Not affected | n/a |
| Red Hat Enterprise Linux 6 | git | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | git | Will not fix | n/a |
| Red Hat Fuse 7 | git | Will not fix | n/a |
| Red Hat Software Collections | rh-git227-git | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
While the described bug in Git presents a significant security concern, it falls short of being categorized as Critical due to several factors. The exploit requires a specific set of conditions, such as repositories with submodules and the presence of symbolic link support. Additionally, successful exploitation relies on users cloning repositories from untrusted sources, limiting its scope compared to critical vulnerabilities that may be remotely exploitable or affect a broader range of use cases. However, the potential impact of remote code execution during cloning operations underscores the importance of promptly applying patches and exercising caution when interacting with Git repositories, emphasizing its significant severity within the realm of software security.
Red Hat mitigation
One preventative measure is to disable symbolic link support. This can be accomplished by running the command git config --global core.symlinks false. Another temporary option is to avoid using the --recurse-submodules setting with untrusted git repos.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
1 other source (GitHub) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 29, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (32 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 29.23% (0.29234) | 98.12th | v5 (v2026.06.15) |
| Aug 4, 2026 | 29.23% (0.29234) | 97.98th | v5 (v2026.06.15) |
| Jun 23, 2026 | 25.33% (0.25334) | 97.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 22.53% (0.22529) | 97.41th | v5 (v2026.06.15) |
| Jun 11, 2026 | 80.84% (0.80837) | 99.17th | v4 (v2025.03.14) |
| May 28, 2026 | 82.07% (0.82068) | 99.23th | v4 (v2025.03.14) |
| May 25, 2026 | 79.53% (0.79527) | 99.10th | v4 (v2025.03.14) |
| May 22, 2026 | 81.34% (0.81337) | 99.19th | v4 (v2025.03.14) |
| Nov 23, 2025 | 79.87% (0.79871) | 99.04th | v4 (v2025.03.14) |
| Nov 21, 2025 | 81.62% (0.81615) | 99.13th | v4 (v2025.03.14) |
| Nov 18, 2025 | 68.01% (0.68011) | 98.61th | v4 (v2025.03.14) |
| Oct 21, 2025 | 80.11% (0.80112) | 99.06th | v4 (v2025.03.14) |
| Oct 19, 2025 | 78.46% (0.78456) | 98.98th | v4 (v2025.03.14) |
| Oct 18, 2025 | 76.72% (0.76721) | 98.89th | v4 (v2025.03.14) |
| Sep 7, 2025 | 78.93% (0.78934) | 99.02th | v4 (v2025.03.14) |
| Aug 3, 2025 | 77.56% (0.77561) | 98.95th | v4 (v2025.03.14) |
| Jul 26, 2025 | 79.56% (0.79561) | 99.03th | v4 (v2025.03.14) |
| Jul 16, 2025 | 81.90% (0.81899) | 99.14th | v4 (v2025.03.14) |
| Jul 5, 2025 | 79.92% (0.79918) | 99.04th | v4 (v2025.03.14) |
| Jun 22, 2025 | 81.16% (0.81155) | 99.10th | v4 (v2025.03.14) |
| Jun 17, 2025 | 73.19% (0.73193) | 98.70th | v4 (v2025.03.14) |
| Jun 14, 2025 | 74.46% (0.74460) | 98.77th | v4 (v2025.03.14) |
| Jun 13, 2025 | 73.19% (0.73193) | 98.70th | v4 (v2025.03.14) |
| May 16, 2025 | 71.00% (0.70998) | 98.60th | v4 (v2025.03.14) |
| May 15, 2025 | 72.37% (0.72369) | 98.66th | v4 (v2025.03.14) |
| Apr 15, 2025 | 71.00% (0.70998) | 98.58th | v4 (v2025.03.14) |
| Mar 17, 2025 | 66.68% (0.66677) | 98.41th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00152) | 52.77th | v3 (v2023.03.01) |
| Jun 27, 2024 | 0.15% (0.00152) | 51.65th | v3 (v2023.03.01) |
| Jun 11, 2024 | 0.10% (0.00095) | 40.06th | v3 (v2023.03.01) |
| May 24, 2024 | 0.06% (0.00064) | 27.30th | v3 (v2023.03.01) |
| May 15, 2024 | 0.04% (0.00045) | 14.63th | v3 (v2023.03.01) |
References (12)
- http://www.openwall.com/lists/oss-security/2024/05/14/2
- https://access.redhat.com/security/cve/CVE-2024-32002 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2280421 Issue Tracking
- https://git-scm.com/docs/git-clone#Documentation/git-clone.txt---recurse-submodulesltpathspecgt x_refsource_MISCNot Applicable
- https://git-scm.com/docs/git-config#Documentation/git-config.txt-coresymlinks x_refsource_MISCNot Applicable
- https://github.com/git/git/commit/97065761333fd62db1912d81b489db938d8c991d x_refsource_MISCPatch
- https://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html
- https://lists.debian.org/debian-lts-announce/2024/09/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S4CK4IYTXEOBZTEM5K3T6LWOIZ3S44AR/
- https://nvd.nist.gov/vuln/detail/CVE-2024-32002
- https://www.cve.org/CVERecord?id=CVE-2024-32002
Change history (0)
No recorded changes yet.