Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 27 articles for you...
217

Oracle Linux 9 ELSA-2025-7409 moderate: git security update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7409 http://linux.oracle.com/errata/ELSA-2025-7409.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: git-2.47.1-2.el9_6.x86_64.rpm git-all-2.47.1-2.el9_6.noarch.rpm git-core-2.47.1-2.el9_6.x86_64.rpm git-core-doc-2.47.1-2.el9_6.noarch.rpm git-credential-libsecret-2.47.1-2.el9_6.x86_64.rpm git-daemon-2.47.1-2.el9_6.x86_64.rpm git-email-2.47.1-2.el9_6.noarch.rpm git-gui-2.47.1-2.el9_6.noarch.rpm git-instaweb-2.47.1-2.el9_6.noarch.rpm git-subtree-2.47.1-2.el9_6.x86_64.rpm git-svn-2.47.1-2.el9_6.noarch.rpm gitk-2.47.1-2.el9_6.noarch.rpm gitweb-2.47.1-2.el9_6.noarch.rpm perl-Git-2.47.1-2.el9_6.noarch.rpm perl-Git-SVN-2.47.1-2.el9_6.noarch.rpm aarch64: git-2.47.1-2.el9_6.aarch64.rpm git-all-2.47.1-2.el9_6.noarch.rpm git-core-2.47.1-2.el9_6.aarch64.rpm git-core-doc-2.47.1-2.el9_6.noarch.rpm git-credential-libsecret-2.47.1-2.el9_6.aarch64.rpm git-daemon-2.47.1-2.el9_6.aarch64.rpm git-email-2.47.1-2.el9_6.noarch.rpm git-gui-2.47.1-2.el9_6.noarch.rpm git-instaweb-2.47.1-2.el9_6.noarch.rpm git-subtree-2.47.1-2.el9_6.aarch64.rpm git-svn-2.47.1-2.el9_6.noarch.rpm gitk-2.47.1-2.el9_6.noarch.rpm gitweb-2.47.1-2.el9_6.noarch.rpm perl-Git-2.47.1-2.el9_6.noarch.rpm perl-Git-SVN-2.47.1-2.el9_6.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//git-2.47.1-2.el9_6.src.rpm Related CVEs: CVE-2024-52005 Description of changes: [2.47.1-2] - add the option to sanitize sideband channel messages - Resolves: RHEL-84513 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2025-7410 enhances OpenSSL to address security flaws, now available on Unbreakable Linux Network.. Oracle Linux Updates, Git Security Patch, Unbreakable Network, ELSA Security Advisory, Linux RPMs. . LinuxSecurity.comTeam

Calendar 2 May 23, 2025 Oracle
99

Slackware 15.0: 2024-136-02 Critical: Git Local Clone Code Execution

New git packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] git (SSA:2024-136-02) New git packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/git-2.39.4-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: Recursive clones on case-insensitive filesystems that support symbolic links are susceptible to case confusion that can be exploited to execute just-cloned code during the clone operation. Repositories can be configured to execute arbitrary code during local clones. To address this, the ownership checks introduced in v2.30.3 are now extended to cover cloning local repositories. Local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. When cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the objects/ directory. It is supposed to be safe to clone untrusted repositories, even those unpacked from zip archives or tarballs originating from untrusted sources, but Git can be tricked to run arbitrary code as part of the clone. For more information, see: https://www.cve.org/CVERecord?id=CVE-2024-32002 https://www.cve.org/CVERecord?id=CVE-2024-32004 https://www.cve.org/CVERecord?id=CVE-2024-32020 https://www.cve.org/CVERecord?id=CVE-2024-32021 https://www.cve.org/CVERecord?id=CVE-2024-32465 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU OpenSource Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 837b659cb32a07eed09bf4de30b72741 git-2.39.4-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 530b3158ef258881e1a340baff5d61b5 git-2.39.4-x86_64-1_slack15.0.txz Slackware -current package: 0f6950f7d7f336e7aa2d47d4a4711bc9 d/git-2.45.1-i586-1.txz Slackware x86_64 -current package: 685fddae35e6b5d4366104f1c05ccd43 d/git-2.45.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg git-2.39.4-i586-1_slack15.0.txz +-----+ . Updated git components for Slackware 15.0 address significant vulnerabilities linked to local repository duplication and execution threats.. Slackware Updates,Github Security Fix,Local Clone Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 16, 2024 Critical Slackware
100

SUSE: 2023:4457-2 Important Update for bci/python Security Issues

The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3356-1 Container Tags : bci/python:3 , bci/python:3-12.2 , bci/python:3.11 , bci/python:3.11-12.2 , bci/python:latest Container Release : 12.2 Severity : important Type : security References : 1215533 1215713 CVE-2023-35945 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3994-1 Released: Fri Oct 6 13:44:15 2023 Summary: Recommended update for git Type: recommended Severity: moderate References: 1215533 This update for git fixes the following issues: - Downgrade openssh dependency to recommends (bsc#1215533) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3997-1 Released: Fri Oct 6 14:13:56 2023 Summary: Security update for nghttp2 Type: security Severity: important References: 1215713,CVE-2023-35945 This update for nghttp2 fixes the following issues: - CVE-2023-35945: Fixed memory leak when PUSH_PROMISE or HEADERS frame cannot be sent (bsc#1215713). The following package changes have been done: - libnghttp2-14-1.40.0-150200.9.1 updated - git-core-2.35.3-150300.10.30.1 updated - libcbor0-0.5.0-150100.4.6.1 removed - libedit0-3.1.snap20150325-2.12 removed - libfido2-1-1.13.0-150400.5.6.1 removed - libhidapi-hidraw0-0.10.1-150300.3.2.1 removed - libudev1-249.16-150400.8.33.1 removed - openssh-clients-8.4p1-150300.3.22.1 removed - openssh-common-8.4p1-150300.3.22.1 removed - openssh-fips-8.4p1-150300.3.22.1 removed . Crucial security patch released for bci/python container tackling various vulnerabilities, including critical memoryleak concerns.. bci/python, security update, container patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 10, 2023 Important SuSE
217

Oracle Linux 8 ELSA-2023-3246 Important: Git Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3246 https://linux.oracle.com/errata/ELSA-2023-3246.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: git-2.39.3-1.el8_8.x86_64.rpm git-all-2.39.3-1.el8_8.noarch.rpm git-core-2.39.3-1.el8_8.x86_64.rpm git-core-doc-2.39.3-1.el8_8.noarch.rpm git-credential-libsecret-2.39.3-1.el8_8.x86_64.rpm git-daemon-2.39.3-1.el8_8.x86_64.rpm git-email-2.39.3-1.el8_8.noarch.rpm git-gui-2.39.3-1.el8_8.noarch.rpm git-instaweb-2.39.3-1.el8_8.noarch.rpm git-subtree-2.39.3-1.el8_8.x86_64.rpm git-svn-2.39.3-1.el8_8.noarch.rpm gitk-2.39.3-1.el8_8.noarch.rpm gitweb-2.39.3-1.el8_8.noarch.rpm perl-Git-2.39.3-1.el8_8.noarch.rpm perl-Git-SVN-2.39.3-1.el8_8.noarch.rpm aarch64: git-2.39.3-1.el8_8.aarch64.rpm git-all-2.39.3-1.el8_8.noarch.rpm git-core-2.39.3-1.el8_8.aarch64.rpm git-core-doc-2.39.3-1.el8_8.noarch.rpm git-credential-libsecret-2.39.3-1.el8_8.aarch64.rpm git-daemon-2.39.3-1.el8_8.aarch64.rpm git-email-2.39.3-1.el8_8.noarch.rpm git-gui-2.39.3-1.el8_8.noarch.rpm git-instaweb-2.39.3-1.el8_8.noarch.rpm git-subtree-2.39.3-1.el8_8.aarch64.rpm git-svn-2.39.3-1.el8_8.noarch.rpm gitk-2.39.3-1.el8_8.noarch.rpm gitweb-2.39.3-1.el8_8.noarch.rpm perl-Git-2.39.3-1.el8_8.noarch.rpm perl-Git-SVN-2.39.3-1.el8_8.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//git-2.39.3-1.el8_8.src.rpm Related CVEs: CVE-2023-22490 CVE-2023-23946 CVE-2023-25652 CVE-2023-25815 CVE-2023-29007 Description of changes: [2.39.3-1] - Update to 2.39.3 - Resolves: #2188364, #2188373, #2190157, #2190158 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The Oracle Linux Advisory ELSA-2023-3250 addresses critical updates for the PostgreSQL database, resolving important vulnerabilities linked to various CVE entries.. Oracle Linux Advisory,gitsecurity update,security issues,git software update,Oracle ELSA-2023-3246. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 26, 2023 Important Oracle
200

SciLinux SL7: SLSA-2023-3263-1 Important Git Update and Threats

git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (CVE-2023-25652) * git: arbitrary configuration injection when renaming or deleting a section from a configuration file (CVE-2023-29007) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and oth [More...]. Synopsis: Important: git security update Advisory ID: SLSA-2023:3263-1 Issue Date: 2023-05-24 CVE Numbers: CVE-2023-25652 CVE-2023-29007 -- Security Fix(es): * git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (CVE-2023-25652) * git: arbitrary configuration injection when renaming or deleting a section from a configuration file (CVE-2023-29007) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 git-1.8.3.1-25.el7_9.x86_64.rpm git-daemon-1.8.3.1-25.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-25.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-25.el7_9.x86_64.rpm git-svn-1.8.3.1-25.el7_9.x86_64.rpm noarch emacs-git-1.8.3.1-25.el7_9.noarch.rpm emacs-git-el-1.8.3.1-25.el7_9.noarch.rpm git-all-1.8.3.1-25.el7_9.noarch.rpm git-bzr-1.8.3.1-25.el7_9.noarch.rpm git-cvs-1.8.3.1-25.el7_9.noarch.rpm git-email-1.8.3.1-25.el7_9.noarch.rpm git-gui-1.8.3.1-25.el7_9.noarch.rpm git-hg-1.8.3.1-25.el7_9.noarch.rpm git-instaweb-1.8.3.1-25.el7_9.noarch.rpm git-p4-1.8.3.1-25.el7_9.noarch.rpm gitk-1.8.3.1-25.el7_9.noarch.rpm gitweb-1.8.3.1-25.el7_9.noarch.rpm perl-Git-1.8.3.1-25.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-25.el7_9.noarch.rpm - Scientific Linux Development Team . A vital patch for Git resolves severe vulnerabilities that could facilitate unrestricted configuration insertion and risk unwanted filereplacements.. Git Security, Arbitrary Configuration Injection, SL7 Updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 24, 2023 Important Scientific Linux
217

Oracle Linux 7 ELSA-2023-3263 Important: Git Fix Critical Threats

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3263 https://linux.oracle.com/errata/ELSA-2023-3263.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: git-1.8.3.1-25.el7_9.aarch64.rpm perl-Git-1.8.3.1-25.el7_9.noarch.rpm emacs-git-1.8.3.1-25.el7_9.noarch.rpm emacs-git-el-1.8.3.1-25.el7_9.noarch.rpm git-all-1.8.3.1-25.el7_9.noarch.rpm git-bzr-1.8.3.1-25.el7_9.noarch.rpm git-cvs-1.8.3.1-25.el7_9.noarch.rpm git-daemon-1.8.3.1-25.el7_9.aarch64.rpm git-email-1.8.3.1-25.el7_9.noarch.rpm git-gnome-keyring-1.8.3.1-25.el7_9.aarch64.rpm git-gui-1.8.3.1-25.el7_9.noarch.rpm git-hg-1.8.3.1-25.el7_9.noarch.rpm git-instaweb-1.8.3.1-25.el7_9.noarch.rpm gitk-1.8.3.1-25.el7_9.noarch.rpm git-p4-1.8.3.1-25.el7_9.noarch.rpm git-svn-1.8.3.1-25.el7_9.aarch64.rpm gitweb-1.8.3.1-25.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-25.el7_9.noarch.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//git-1.8.3.1-25.el7_9.src.rpm Related CVEs: CVE-2023-25652 CVE-2023-29007 Description of changes: [1.8.3.1-25] - Fixes CVE-2023-25652 and CVE-2023-29007 - Resolves: #2188354, #2188365 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 7 patch release for curl mitigates several security flaws along with RPM packages and corrective measures.. Oracle Linux Update, Git Fix, Security Patch, Linux Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 24, 2023 Important Oracle
98

Red Hat Enterprise Linux 9 RHSA-2023:2319-01 Moderate: Git Security

An update for git is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: git security and bug fix update Advisory ID: RHSA-2023:2319-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2319 Issue date: 2023-05-09 CVE Names: CVE-2022-24765 CVE-2022-29187 CVE-2022-39253 CVE-2022-39260 ==================================================================== 1. Summary: An update for git is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. Security Fix(es): * git: On multi-user machines Git users might find themselves unexpectedly in a Git worktree (CVE-2022-24765) * git: Bypass of safe.directory protections (CVE-2022-29187) *git: exposure of sensitive information to a malicious actor (CVE-2022-39253) * git: git shell function that splits command arguments can lead to arbitrary heap writes. (CVE-2022-39260) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2073414 - CVE-2022-24765 git: On multi-user machines Git users might find themselves unexpectedly in a Git worktree 2107439 - CVE-2022-29187 git: Bypass of safe.directory protections 2137422 - CVE-2022-39253 git: exposure of sensitive information to a malicious actor 2137423 - CVE-2022-39260 git: git shell function that splits command arguments can lead to arbitrary heap writes. 2139379 - Rebase git to 2.39 version [rhel-9.2] 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: git-2.39.1-1.el9.src.rpm aarch64: git-2.39.1-1.el9.aarch64.rpm git-core-2.39.1-1.el9.aarch64.rpm git-core-debuginfo-2.39.1-1.el9.aarch64.rpm git-credential-libsecret-2.39.1-1.el9.aarch64.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.aarch64.rpm git-daemon-2.39.1-1.el9.aarch64.rpm git-daemon-debuginfo-2.39.1-1.el9.aarch64.rpm git-debuginfo-2.39.1-1.el9.aarch64.rpm git-debugsource-2.39.1-1.el9.aarch64.rpm git-subtree-2.39.1-1.el9.aarch64.rpm noarch: git-all-2.39.1-1.el9.noarch.rpm git-core-doc-2.39.1-1.el9.noarch.rpm git-email-2.39.1-1.el9.noarch.rpm git-gui-2.39.1-1.el9.noarch.rpm git-instaweb-2.39.1-1.el9.noarch.rpm git-svn-2.39.1-1.el9.noarch.rpm gitk-2.39.1-1.el9.noarch.rpm gitweb-2.39.1-1.el9.noarch.rpm perl-Git-2.39.1-1.el9.noarch.rpm perl-Git-SVN-2.39.1-1.el9.noarch.rpm ppc64le: git-2.39.1-1.el9.ppc64le.rpm git-core-2.39.1-1.el9.ppc64le.rpm git-core-debuginfo-2.39.1-1.el9.ppc64le.rpm git-credential-libsecret-2.39.1-1.el9.ppc64le.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.ppc64le.rpm git-daemon-2.39.1-1.el9.ppc64le.rpm git-daemon-debuginfo-2.39.1-1.el9.ppc64le.rpm git-debuginfo-2.39.1-1.el9.ppc64le.rpm git-debugsource-2.39.1-1.el9.ppc64le.rpm git-subtree-2.39.1-1.el9.ppc64le.rpm s390x: git-2.39.1-1.el9.s390x.rpm git-core-2.39.1-1.el9.s390x.rpm git-core-debuginfo-2.39.1-1.el9.s390x.rpm git-credential-libsecret-2.39.1-1.el9.s390x.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.s390x.rpm git-daemon-2.39.1-1.el9.s390x.rpm git-daemon-debuginfo-2.39.1-1.el9.s390x.rpm git-debuginfo-2.39.1-1.el9.s390x.rpm git-debugsource-2.39.1-1.el9.s390x.rpm git-subtree-2.39.1-1.el9.s390x.rpm x86_64: git-2.39.1-1.el9.x86_64.rpm git-core-2.39.1-1.el9.x86_64.rpm git-core-debuginfo-2.39.1-1.el9.x86_64.rpm git-credential-libsecret-2.39.1-1.el9.x86_64.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.x86_64.rpm git-daemon-2.39.1-1.el9.x86_64.rpm git-daemon-debuginfo-2.39.1-1.el9.x86_64.rpm git-debuginfo-2.39.1-1.el9.x86_64.rpm git-debugsource-2.39.1-1.el9.x86_64.rpm git-subtree-2.39.1-1.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-24765 https://access.redhat.com/security/cve/CVE-2022-29187 https://access.redhat.com/security/cve/CVE-2022-39253 https://access.redhat.com/security/cve/CVE-2022-39260 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZFo03tzjgjWX9erEAQhYSg//bKkon2hHN6jSsXXntqw9ViT5zo9r/KTD cV+t7GM4ipVK8j4EW8EnQKrJBWAzsEhqM2vh9MvM/PpTQ2I/JP53YbTed0qgxE3T SU07XMVbh1BA7OKyJ+eKfWJLBT03/VzzaepqQPwyHyFDAegJ/L9DlZOkHc9NJrfa R+N2Hde/TmUlnRl737ltWtQHE1QSTV1PQZuXb3AEWm6FDe7O62F0GpsuIWj1z8oo IIDLHRjp/mCqT6/A70NIRQvcwhLfRYYMOezKL80iGi7WwRokwEScDFE+gzB9FLrf pjNBFZkQVVxMVYOejArmPuLINaEdZJo/HAOiEtw9gOTzALyKFbWwOHDmSzz1hgbz kqFtZgwnpVZNs3UubXCgWeP4aU9xueZeyBHKNQKVERODtrKFt5jbpPrXu6qGyP9O 6GSgMbUDO5OMqOhTKQiMbKj5gO2DfOIO6vNP5eFwvSXPJG0ZlPIzAJD1cwZdtsVK wWBIMfjjc8zUh8OYm+CWg/lgpZLkQxe/wtFcC7Pw1u7nkN95npMXM3O75R8xe1zg xsa+wzjCmVRwrO2gLnT7/NUkY3saShCvBD+A82trnasbVlI/49oiojZY1PI3CZtz afQDlfLvgygNkV3e5CGe5p9PILwmFbrpALV43dEz6eY+MbeuoE6I7ON8tYtmx4Ds hOpSLJjOLjE=YQQZ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Fresh git upgrade ready for Red Hat Enterprise Linux 9 categorized as moderate severity. Implement security enhancements and resolve issues now.. Red Hat Enterprise Linux, Git Update, Security Advisory, Bug Fixes. . LinuxSecurity.com Team

Calendar 2 May 09, 2023 Red Hat
98

Red Hat: RHSA-2023:0978-01 Important: Git Integer And Heap Overflow

An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: git security update Advisory ID: RHSA-2023:0978-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0978 Issue date: 2023-02-28 CVE Names: CVE-2022-23521 CVE-2022-41903 ==================================================================== 1. Summary: An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their officialrepositories, but also makes it possible for the user to work with no network connection. Security Fix(es): * git: gitattributes parsing integer overflow (CVE-2022-23521) * git: Heap overflow in `git archive`, `git log --format` leading to RCE (CVE-2022-41903) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2162055 - CVE-2022-23521 git: gitattributes parsing integer overflow 2162056 - CVE-2022-41903 git: Heap overflow in `git archive`, `git log --format` leading to RCE 6. Package List: Red Hat Enterprise Linux Client Optional (v. 7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: perl-Git-1.8.3.1-24.el7_9.noarch.rpm ppc64: git-1.8.3.1-24.el7_9.ppc64.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64.rpm ppc64le: git-1.8.3.1-24.el7_9.ppc64le.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64le.rpm s390x: git-1.8.3.1-24.el7_9.s390x.rpm git-debuginfo-1.8.3.1-24.el7_9.s390x.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm ppc64: git-daemon-1.8.3.1-24.el7_9.ppc64.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.ppc64.rpm git-svn-1.8.3.1-24.el7_9.ppc64.rpm ppc64le: git-daemon-1.8.3.1-24.el7_9.ppc64le.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64le.rpm git-gnome-keyring-1.8.3.1-24.el7_9.ppc64le.rpm git-svn-1.8.3.1-24.el7_9.ppc64le.rpm s390x: git-daemon-1.8.3.1-24.el7_9.s390x.rpm git-debuginfo-1.8.3.1-24.el7_9.s390x.rpm git-gnome-keyring-1.8.3.1-24.el7_9.s390x.rpm git-svn-1.8.3.1-24.el7_9.s390x.rpm x86_64: git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: perl-Git-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-23521 https://access.redhat.com/security/cve/CVE-2022-41903 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY/3ztdzjgjWX9erEAQgw4g//fI6hgVC3Ds7f4CigbDHZ3G6uJVNLgZCo ePiMQ7yQ7QB4UHxl7tUlPxA57z+SdAnSWYXMxE/Q38b8asujPfn+RC/nfRYuDkjy 03Wl5Jw2x7ctlcab+cX3s/qZ77u4HlUF3Hv0bTdMOF6U3CjLzU7kywPVzWzGid4o nDKE+NjehScG/UL6ZzkvaKQr7UQk8Uak7gpoCtMsiTWFkAxA9y3xbzBdnNL77PMK tYpIvbGCdP/NgIGvOi2iCTIbKQf+mza6EBJUWMzjstR766icUdzb0NSel9V3tP0s w25oR17hCUnkSXy3b/eWFccuodGahO4p/DBxVFfOwVk16q0BkAqm9r8TGqijuNhp EDsIfJzHDanCqQEUjjWiwxPNmgUtk6/kqp1A8Vrz0O0OaiTQrWw0LHbwosAj5t1+ Q5bA9F0iBsBqjxEchrUo5fOPtTV7KNjN5KHA8KQACgXZ+QaT5oCLcOGoxyJzLizO eYENky+YuqJbBMo71DsJXMK8ovCqRYKzFI6w3zW9As0imZK72O0jtJYkxeV7E2uw N16NG92J3vgn0sq2zb08uxhQY/6YFNd2RDPZB+i4Vx40jZu95gfVNihpD/O9b2dZ AUtORmrxTGmgQvR4/0kyuEAW3p94BxA0M0fS7NmH9qfq2HU8tJLoh09t2kM3dX5/ 7Pkb0u+dNFE=sL46 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent security bulletin for Red Hat Enterprise Linux 7 emphasizes critical updates on git software, aimed at serious heap and integer overflow vulnerabilities affecting system integrity. Git Update, RHEL Security, Security Advisory, Software Patching, Issue Resolution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 28, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here