Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-12278
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-12278 is a security vulnerability discovered in libgit2 versions before 0.28.4 and 0.9x before 0.99.0. The vulnerability was disclosed in April 2020 and affects the path.c component of libgit2, which mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This vulnerability could potentially allow remote code execution when cloning a repository (NVD, Ubuntu Security).

Technical details

The vulnerability stems from the way path.c handles NTFS Alternate Data Streams. The issue is similar to CVE-2019-1352 and affects the path handling mechanism when dealing with equivalent filenames on NTFS filesystems. The vulnerability has been assigned a CVSS v3.1 Base Score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a critical severity level with network attack vector, low attack complexity, and no required privileges or user interaction (NVD).

Impact

The vulnerability could allow an attacker to execute remote code when a repository is cloned. This is particularly concerning as it affects not only Windows systems but also other platforms that interact with NTFS filesystems, including systems accessing NTFS through mounted network shares (Debian Security).

Exploitability

The vulnerability can be exploited when cloning a repository on systems that use or interact with NTFS filesystems. The attack vector involves manipulating filenames using NTFS Alternate Data Streams, which could lead to arbitrary code execution (Ubuntu Security).

Mitigation and workarounds

The vulnerability has been patched in libgit2 version 0.28.4 and 0.99.0. The fix involves implementing proper validation of paths and rejecting any paths that use NTFS Alternate Data Streams. Users are recommended to upgrade to these or later versions. The patches include commits 3f7851e and e1832eb which specifically address the NTFS Alternate Data Stream attacks (Git Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • mingw32-binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management