-
CVSS Score
-The advisory explicitly identifies git_revparse_single and git_index_add as vulnerable C functions in libgit2 that are exposed through the libgit2-sys Rust bindings. The commit diff shows updates to libgit2's index.c and revparse.c files, confirming these are the implementation locations. The third vulnerability in smart transport negotiation isn't tied to a specific named function in the available data, so it's excluded from high-confidence identification.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| libgit2-sys | rust | < 0.16.2 | 0.16.2 |