---
title: "CVE-2024-52005\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-52005?format=md
keywords: index, follow
---

# CVE-2024-52005

Publication date 15 January 2025

Last updated 10 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2024-52005?format=md#impact-score)

Toggle side navigation

## Description

Git is a source code management tool. When cloning from a server (or
fetching, or pushing), informational or error messages are transported from
the remote Git process to the client via the so-called "sideband channel".
These messages will be prefixed with "remote:" and printed directly to the
standard error output. Typically, this standard error output is connected
to a terminal that understands ANSI escape sequences, which Git did not
protect against. Most modern terminals support control sequences that can
be used by a malicious actor to hide and misrepresent information, or to
mislead the user into executing untrusted scripts. As requested on the
git-security mailing list, the patches are under discussion on the public
mailing list. Users are advised to update as soon as possible. Users unable
to upgrade should avoid recursive clones unless they are from trusted
sources.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2024-52005?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| git | 26.04 LTS resolute | Vulnerable, fix deferred |
| 25.10 questing | Ignored end of life, was deferred |
| 25.04 plucky | Ignored end of life, was deferred |
| 24.10 oracular | Ignored end of life, was deferred |
| 24.04 LTS noble | Vulnerable, fix deferred |
| 22.04 LTS jammy | Vulnerable, fix deferred |
| 20.04 LTS focal | Vulnerable, fix deferred |
| 18.04 LTS bionic | Vulnerable, fix deferred |
| 16.04 LTS xenial | Vulnerable, fix deferred |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

as of 2025-02-26, there is no upstream fix for this issue. See
mailing list discussion link.

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2024-52005?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2024-52005?format=md)

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Attack requirements | None |
  | Privileges required | None |
  | User interaction | Active |
  | Vulnerable system - Confidentiality impact | High |
  | Vulnerable system - Integrity impact | High |
  | Vulnerable system - Availability impact | High |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52005)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-52005)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-52005)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-52005)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-52005>
* <https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329>
* <https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net>
* <https://lore.kernel.org/git/8570a129-d66a-465a-905e-0a077c69c409@gmail.com/T/#t>
