gix-packetline Rust Crate Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- gix-packetline (cargo)
- Affected versions
- < 0.21.5
- Patched version
- Not yet available
An early warning has been issued for a vulnerability in the gix-packetline Rust crate that can lead to a denial of service when receiving an empty side-band packet line. This issue affects versions prior to 0.21.5.
What happened
An early warning has been issued regarding a vulnerability in the gix-packetline Rust crate. This crate is reportedly susceptible to a denial of service attack when it receives a side-band packet line with an empty payload. This can be triggered by a malicious Git server during a normal fetch operation. The vulnerability is under investigation and has not yet been exploited in the wild.
The issue is tracked under GHSA-2VH6-HW4J-32WW and affects versions of the gix-packetline crate prior to 0.21.5. The vulnerability allows for a pre-authentication network denial of service attack. It is recommended to monitor for updates to the gix-packetline crate that address this issue. Additionally, consider using a different Git server or implementing additional network security measures to mitigate potential attacks.
What to do about it
- Monitor for updates to the gix-packetline crate that address this issue.
- Consider upgrading to version 0.21.5 or later if available.
- Consider using a different Git server as a temporary measure.
- Implement additional network security measures to mitigate potential attacks.
- No official fix has been published yet. Monitor the sources below for updates.
How 0Day would have caught this
gix-packetline is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using the gix-packetline crate in versions prior to 0.21.5.
What should I do right now?
Monitor for updates to the gix-packetline crate. Consider upgrading to version 0.21.5 or later if available. As a temporary measure, consider using a different Git server and implement additional network security measures.
Is there an official fix available?
No official fix has been published yet. Continue to monitor the sources for updates.