Vulnerability DatabaseRUSTSEC-2024-0353

RUSTSEC-2024-0353
Rust vulnerability analysis and mitigation

Overview

The vulnerability (RUSTSEC-2024-0353) affects gitoxide, a pure Rust implementation of Git, specifically on Windows systems. The issue was disclosed on May 22, 2024, and impacts multiple packages including gitoxide, gix-core, gix, gix-index, gix-ref, gix-worktree, and gix-worktree-state. The vulnerability allows malicious repositories to exploit Windows legacy device names during cloning operations (GitHub Advisory).

Technical details

The vulnerability stems from improper handling of Windows legacy DOS-style device names in two scenarios: First, gix-ref fails to validate reference names before accessing them on disk, leading to device reads. Second, gix-worktree-state incorrectly processes certain path names, resulting in arbitrary data writes to system devices. The issue has been assigned a CVSS v3.1 score of 5.4 (Moderate) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L (GitHub Advisory).

Impact

The vulnerability's impact is primarily limited to Windows systems when cloning untrusted repositories. It can cause indefinite blocking through console input manipulation (using CON or CONIN$) or enable the display of arbitrary messages that appear to come from the application (using CON or CONOUT$). Additionally, it may potentially interfere with serial port operations and cause minor availability degradation (GitHub Advisory).

Exploitability

The vulnerability can be exploited by creating a Git repository containing references or filenames that match Windows legacy device names. Two proof-of-concept exploits have been documented: one using a lightweight tag named 'CON' to demonstrate denial of service, and another using a file named 'CON' to display arbitrary messages that appear to come from the application (GitHub Advisory).

Mitigation and workarounds

Fixed versions have been released for all affected packages: gitoxide (>= 0.36.0), gitoxide-core (>= 0.38.0), gix (>= 0.63.0), gix-index (>= 0.33.0), gix-ref (>= 0.44.0), gix-worktree (>= 0.34.0), and gix-worktree-state (>= 0.11.0). Users should upgrade to these patched versions to mitigate the vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54788HIGH7.5
  • Rust logoRust
  • datadog-opentelemetry
NoYesAug 28, 2026
RUSTSEC-2026-0278HIGH7.3
  • Rust logoRust
  • zbus_polkit
NoYesAug 31, 2026
GHSA-2vh6-hw4j-32wwMEDIUM6.5
  • Rust logoRust
  • gix-packetline
NoYesAug 28, 2026
CVE-2026-53600MEDIUM6.3
  • Rust logoRust
  • zed
NoYesSep 02, 2026
RUSTSEC-2026-0272NONEN/A
  • Rust logoRust
  • stack_dst
NoYesAug 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management