PatchSiren cyber security CVE debrief
CVE-2016-8569 Fedoraproject CVE debrief
CVE-2016-8569 is a denial-of-service issue in libgit2 caused by a NULL pointer dereference in git_oid_nfmt inside commit.c. According to the NVD record, the bug is reachable when processing a crafted object file through a cat-file command. The vulnerability is rated medium severity (CVSS 3.0 5.5) and is primarily an availability issue. The supplied NVD data and downstream advisories indicate that libgit2 versions through 0.24.2 are affected, with vendor package tracking also listed for Fedora and several openSUSE/SUSE builds.
- Vendor
- Fedoraproject
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-03
- Advisory updated
- 2026-05-13
Who should care
Security teams and maintainers who ship libgit2, package it in distributions, or embed it in applications that inspect untrusted repositories or object files. Developers operating tooling that uses cat-file-like workflows should also care, since malformed input can trigger a crash rather than a code execution issue.
Technical summary
The flaw is a CWE-476 NULL pointer dereference in git_oid_nfmt (commit.c). NVD classifies the exploitability as AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, which means the main impact is service interruption and user interaction is required. The CVE description states the issue affects libgit2 before 0.24.3; NVD’s vulnerable CPE data marks libgit2 through 0.24.2 and lists downstream Fedora/openSUSE/SUSE package coverage as well.
Defensive priority
Medium priority, but patch promptly if your environment processes untrusted repositories or object files. Availability-only crashes can still be operationally significant in build systems, package tooling, and automation.
Recommended defensive actions
- Upgrade libgit2 to 0.24.3 or a vendor-backported fixed package.
- Verify downstream distro packages against the relevant Fedora, openSUSE, or SUSE advisories before assuming you are protected.
- Audit applications that embed libgit2 or expose repository/object inspection features to untrusted input.
- Treat crafted repository/object content as untrusted and restrict where feasible until patched versions are deployed.
- If you maintain a fork or vendored copy of libgit2, confirm the fix is present in your tree and rebuild dependent software.
Evidence notes
This debrief is based on the supplied CVE description, the NVD record, and the linked advisories. NVD describes the issue as a NULL pointer dereference in git_oid_nfmt, rates it CVSS 3.0 5.5, assigns CWE-476, and lists libgit2 through 0.24.2 as vulnerable. The enrichment supplied with this item indicates the CVE is not part of CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8569 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8569
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8569 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8569
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.