Medium severity5.5NVD Advisory· Published Oct 14, 2017· Updated May 13, 2026
CVE-2017-15298
CVE-2017-15298
Description
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.
Affected products
5cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- kate.io/blog/git-bomb/nvdExploitThird Party Advisory
- usn.ubuntu.com/3829-1/nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.htmlnvd
News mentions
0No linked articles in our index yet.