This update for git fixes the following issues:
Update from version 2.26.2 to version 2.31.1 (jsc#SLE-18152)
Security fixes:
- CVE-2021-21300: On case-insensitive file systems with support for
symbolic links, if Git is configured globally to apply delay-capable
clean/smudge filters (such as Git LFS), Git could run remote code during
a clone. (bsc#1183026)
Non security changes:
- Add `sysusers` file to create `git-daemon` user.
- Remove `perl-base` and `openssh-server` dependency on `git-core`and
provide a `perl-Git` package. (jsc#SLE-17838)
- `fsmonitor` bug fixes
- Fix `git bisect` to take an annotated tag as a good/bad endpoint
- Fix a corner case in `git mv` on case insensitive systems
- Require only `openssh-clients` where possible (like Tumbleweed or SUSE
Linux Enterprise >= 15 SP3). (bsc#1183580)
- Drop `rsync` requirement, not necessary anymore.
- Use of `pack-redundant` command is discouraged and will...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-2555=1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
git-2.31.1-10.3.1
git-arch-2.31.1-10.3.1
git-core-2.31.1-10.3.1
git-core-debuginfo-2.31.1-10.3.1
git-credential-gnome-keyring-2.31.1-10.3.1
git-credential-gnome-keyring-debuginfo-2.31.1-10.3.1
git-credential-libsecret-2.31.1-10.3.1
git-credential-libsecret-debuginfo-2.31.1-10.3.1
git-cvs-2.31.1-10.3.1
git-daemon-2.31.1-10.3.1
git-daemon-debuginfo-2.31.1-10.3.1
git-debuginfo-2.31.1-10.3.1
git-debugsource-2.31.1-10.3.1
git-email-2.31.1-10.3.1
git-gui-2.31.1-10.3.1
git-p4-2.31.1-10.3.1
git-svn-2.31.1-10.3.1
git-web-2.31.1-10.3.1
gitk-2.31.1-10.3.1
perl-Git-2.31.1-10.3.1
- openSUSE Leap 15.3 (noarch):
git-doc-2.31.1-10.3.1
https://www.suse.com/security/cve/CVE-2021-21300.html
https://bugzilla.suse.com/1168930
https://bugzilla.suse.com/1183026
https://bugzilla.suse.com/1183580
Get the latest Linux and open source security news straight to your inbox.