The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7409 http://linux.oracle.com/errata/ELSA-2025-7409.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: git-2.47.1-2.el9_6.x86_64.rpm git-all-2.47.1-2.el9_6.noarch.rpm git-core-2.47.1-2.el9_6.x86_64.rpm git-core-doc-2.47.1-2.el9_6.noarch.rpm git-credential-libsecret-2.47.1-2.el9_6.x86_64.rpm git-daemon-2.47.1-2.el9_6.x86_64.rpm git-email-2.47.1-2.el9_6.noarch.rpm git-gui-2.47.1-2.el9_6.noarch.rpm git-instaweb-2.47.1-2.el9_6.noarch.rpm git-subtree-2.47.1-2.el9_6.x86_64.rpm git-svn-2.47.1-2.el9_6.noarch.rpm gitk-2.47.1-2.el9_6.noarch.rpm gitweb-2.47.1-2.el9_6.noarch.rpm perl-Git-2.47.1-2.el9_6.noarch.rpm perl-Git-SVN-2.47.1-2.el9_6.noarch.rpm aarch64: git-2.47.1-2.el9_6.aarch64.rpm git-all-2.47.1-2.el9_6.noarch.rpm git-core-2.47.1-2.el9_6.aarch64.rpm git-core-doc-2.47.1-2.el9_6.noarch.rpm git-credential-libsecret-2.47.1-2.el9_6.aarch64.rpm git-daemon-2.47.1-2.el9_6.aarch64.rpm git-email-2.47.1-2.el9_6.noarch.rpm git-gui-2.47.1-2.el9_6.noarch.rpm git-instaweb-2.47.1-2.el9_6.noarch.rpm git-subtree-2.47.1-2.el9_6.aarch64.rpm git-svn-2.47.1-2.el9_6.noarch.rpm gitk-2.47.1-2.el9_6.noarch.rpm gitweb-2.47.1-2.el9_6.noarch.rpm perl-Git-2.47.1-2.el9_6.noarch.rpm perl-Git-SVN-2.47.1-2.el9_6.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//git-2.47.1-2.el9_6.src.rpm Related CVEs: CVE-2024-52005 Description of changes: [2.47.1-2] - add the option to sanitize sideband channel messages - Resolves: RHEL-84513 _______________________________________________ El-errata mailing list
New git packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] git (SSA:2024-136-02) New git packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/git-2.39.4-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: Recursive clones on case-insensitive filesystems that support symbolic links are susceptible to case confusion that can be exploited to execute just-cloned code during the clone operation. Repositories can be configured to execute arbitrary code during local clones. To address this, the ownership checks introduced in v2.30.3 are now extended to cover cloning local repositories. Local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. When cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the objects/ directory. It is supposed to be safe to clone untrusted repositories, even those unpacked from zip archives or tarballs originating from untrusted sources, but Git can be tricked to run arbitrary code as part of the clone. For more information, see: https://www.cve.org/CVERecord?id=CVE-2024-32002 https://www.cve.org/CVERecord?id=CVE-2024-32004 https://www.cve.org/CVERecord?id=CVE-2024-32020 https://www.cve.org/CVERecord?id=CVE-2024-32021 https://www.cve.org/CVERecord?id=CVE-2024-32465 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU OpenSource Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 837b659cb32a07eed09bf4de30b72741 git-2.39.4-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 530b3158ef258881e1a340baff5d61b5 git-2.39.4-x86_64-1_slack15.0.txz Slackware -current package: 0f6950f7d7f336e7aa2d47d4a4711bc9 d/git-2.45.1-i586-1.txz Slackware x86_64 -current package: 685fddae35e6b5d4366104f1c05ccd43 d/git-2.45.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg git-2.39.4-i586-1_slack15.0.txz +-----+ . Updated git components for Slackware 15.0 address significant vulnerabilities linked to local repository duplication and execution threats.. Slackware Updates,Github Security Fix,Local Clone Risks. . Severity: Critical. LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3356-1 Container Tags : bci/python:3 , bci/python:3-12.2 , bci/python:3.11 , bci/python:3.11-12.2 , bci/python:latest Container Release : 12.2 Severity : important Type : security References : 1215533 1215713 CVE-2023-35945 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3994-1 Released: Fri Oct 6 13:44:15 2023 Summary: Recommended update for git Type: recommended Severity: moderate References: 1215533 This update for git fixes the following issues: - Downgrade openssh dependency to recommends (bsc#1215533) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3997-1 Released: Fri Oct 6 14:13:56 2023 Summary: Security update for nghttp2 Type: security Severity: important References: 1215713,CVE-2023-35945 This update for nghttp2 fixes the following issues: - CVE-2023-35945: Fixed memory leak when PUSH_PROMISE or HEADERS frame cannot be sent (bsc#1215713). The following package changes have been done: - libnghttp2-14-1.40.0-150200.9.1 updated - git-core-2.35.3-150300.10.30.1 updated - libcbor0-0.5.0-150100.4.6.1 removed - libedit0-3.1.snap20150325-2.12 removed - libfido2-1-1.13.0-150400.5.6.1 removed - libhidapi-hidraw0-0.10.1-150300.3.2.1 removed - libudev1-249.16-150400.8.33.1 removed - openssh-clients-8.4p1-150300.3.22.1 removed - openssh-common-8.4p1-150300.3.22.1 removed - openssh-fips-8.4p1-150300.3.22.1 removed . Crucial security patch released for bci/python container tackling various vulnerabilities, including critical memoryleak concerns.. bci/python, security update, container patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3246 https://linux.oracle.com/errata/ELSA-2023-3246.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: git-2.39.3-1.el8_8.x86_64.rpm git-all-2.39.3-1.el8_8.noarch.rpm git-core-2.39.3-1.el8_8.x86_64.rpm git-core-doc-2.39.3-1.el8_8.noarch.rpm git-credential-libsecret-2.39.3-1.el8_8.x86_64.rpm git-daemon-2.39.3-1.el8_8.x86_64.rpm git-email-2.39.3-1.el8_8.noarch.rpm git-gui-2.39.3-1.el8_8.noarch.rpm git-instaweb-2.39.3-1.el8_8.noarch.rpm git-subtree-2.39.3-1.el8_8.x86_64.rpm git-svn-2.39.3-1.el8_8.noarch.rpm gitk-2.39.3-1.el8_8.noarch.rpm gitweb-2.39.3-1.el8_8.noarch.rpm perl-Git-2.39.3-1.el8_8.noarch.rpm perl-Git-SVN-2.39.3-1.el8_8.noarch.rpm aarch64: git-2.39.3-1.el8_8.aarch64.rpm git-all-2.39.3-1.el8_8.noarch.rpm git-core-2.39.3-1.el8_8.aarch64.rpm git-core-doc-2.39.3-1.el8_8.noarch.rpm git-credential-libsecret-2.39.3-1.el8_8.aarch64.rpm git-daemon-2.39.3-1.el8_8.aarch64.rpm git-email-2.39.3-1.el8_8.noarch.rpm git-gui-2.39.3-1.el8_8.noarch.rpm git-instaweb-2.39.3-1.el8_8.noarch.rpm git-subtree-2.39.3-1.el8_8.aarch64.rpm git-svn-2.39.3-1.el8_8.noarch.rpm gitk-2.39.3-1.el8_8.noarch.rpm gitweb-2.39.3-1.el8_8.noarch.rpm perl-Git-2.39.3-1.el8_8.noarch.rpm perl-Git-SVN-2.39.3-1.el8_8.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//git-2.39.3-1.el8_8.src.rpm Related CVEs: CVE-2023-22490 CVE-2023-23946 CVE-2023-25652 CVE-2023-25815 CVE-2023-29007 Description of changes: [2.39.3-1] - Update to 2.39.3 - Resolves: #2188364, #2188373, #2190157, #2190158 _______________________________________________ El-errata mailing list
git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (CVE-2023-25652) * git: arbitrary configuration injection when renaming or deleting a section from a configuration file (CVE-2023-29007) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and oth [More...]. Synopsis: Important: git security update Advisory ID: SLSA-2023:3263-1 Issue Date: 2023-05-24 CVE Numbers: CVE-2023-25652 CVE-2023-29007 -- Security Fix(es): * git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (CVE-2023-25652) * git: arbitrary configuration injection when renaming or deleting a section from a configuration file (CVE-2023-29007) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 git-1.8.3.1-25.el7_9.x86_64.rpm git-daemon-1.8.3.1-25.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-25.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-25.el7_9.x86_64.rpm git-svn-1.8.3.1-25.el7_9.x86_64.rpm noarch emacs-git-1.8.3.1-25.el7_9.noarch.rpm emacs-git-el-1.8.3.1-25.el7_9.noarch.rpm git-all-1.8.3.1-25.el7_9.noarch.rpm git-bzr-1.8.3.1-25.el7_9.noarch.rpm git-cvs-1.8.3.1-25.el7_9.noarch.rpm git-email-1.8.3.1-25.el7_9.noarch.rpm git-gui-1.8.3.1-25.el7_9.noarch.rpm git-hg-1.8.3.1-25.el7_9.noarch.rpm git-instaweb-1.8.3.1-25.el7_9.noarch.rpm git-p4-1.8.3.1-25.el7_9.noarch.rpm gitk-1.8.3.1-25.el7_9.noarch.rpm gitweb-1.8.3.1-25.el7_9.noarch.rpm perl-Git-1.8.3.1-25.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-25.el7_9.noarch.rpm - Scientific Linux Development Team . A vital patch for Git resolves severe vulnerabilities that could facilitate unrestricted configuration insertion and risk unwanted filereplacements.. Git Security, Arbitrary Configuration Injection, SL7 Updates. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3263 https://linux.oracle.com/errata/ELSA-2023-3263.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: git-1.8.3.1-25.el7_9.aarch64.rpm perl-Git-1.8.3.1-25.el7_9.noarch.rpm emacs-git-1.8.3.1-25.el7_9.noarch.rpm emacs-git-el-1.8.3.1-25.el7_9.noarch.rpm git-all-1.8.3.1-25.el7_9.noarch.rpm git-bzr-1.8.3.1-25.el7_9.noarch.rpm git-cvs-1.8.3.1-25.el7_9.noarch.rpm git-daemon-1.8.3.1-25.el7_9.aarch64.rpm git-email-1.8.3.1-25.el7_9.noarch.rpm git-gnome-keyring-1.8.3.1-25.el7_9.aarch64.rpm git-gui-1.8.3.1-25.el7_9.noarch.rpm git-hg-1.8.3.1-25.el7_9.noarch.rpm git-instaweb-1.8.3.1-25.el7_9.noarch.rpm gitk-1.8.3.1-25.el7_9.noarch.rpm git-p4-1.8.3.1-25.el7_9.noarch.rpm git-svn-1.8.3.1-25.el7_9.aarch64.rpm gitweb-1.8.3.1-25.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-25.el7_9.noarch.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//git-1.8.3.1-25.el7_9.src.rpm Related CVEs: CVE-2023-25652 CVE-2023-29007 Description of changes: [1.8.3.1-25] - Fixes CVE-2023-25652 and CVE-2023-29007 - Resolves: #2188354, #2188365 _______________________________________________ El-errata mailing list
An update for git is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: git security and bug fix update Advisory ID: RHSA-2023:2319-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2319 Issue date: 2023-05-09 CVE Names: CVE-2022-24765 CVE-2022-29187 CVE-2022-39253 CVE-2022-39260 ==================================================================== 1. Summary: An update for git is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. Security Fix(es): * git: On multi-user machines Git users might find themselves unexpectedly in a Git worktree (CVE-2022-24765) * git: Bypass of safe.directory protections (CVE-2022-29187) *git: exposure of sensitive information to a malicious actor (CVE-2022-39253) * git: git shell function that splits command arguments can lead to arbitrary heap writes. (CVE-2022-39260) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2073414 - CVE-2022-24765 git: On multi-user machines Git users might find themselves unexpectedly in a Git worktree 2107439 - CVE-2022-29187 git: Bypass of safe.directory protections 2137422 - CVE-2022-39253 git: exposure of sensitive information to a malicious actor 2137423 - CVE-2022-39260 git: git shell function that splits command arguments can lead to arbitrary heap writes. 2139379 - Rebase git to 2.39 version [rhel-9.2] 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: git-2.39.1-1.el9.src.rpm aarch64: git-2.39.1-1.el9.aarch64.rpm git-core-2.39.1-1.el9.aarch64.rpm git-core-debuginfo-2.39.1-1.el9.aarch64.rpm git-credential-libsecret-2.39.1-1.el9.aarch64.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.aarch64.rpm git-daemon-2.39.1-1.el9.aarch64.rpm git-daemon-debuginfo-2.39.1-1.el9.aarch64.rpm git-debuginfo-2.39.1-1.el9.aarch64.rpm git-debugsource-2.39.1-1.el9.aarch64.rpm git-subtree-2.39.1-1.el9.aarch64.rpm noarch: git-all-2.39.1-1.el9.noarch.rpm git-core-doc-2.39.1-1.el9.noarch.rpm git-email-2.39.1-1.el9.noarch.rpm git-gui-2.39.1-1.el9.noarch.rpm git-instaweb-2.39.1-1.el9.noarch.rpm git-svn-2.39.1-1.el9.noarch.rpm gitk-2.39.1-1.el9.noarch.rpm gitweb-2.39.1-1.el9.noarch.rpm perl-Git-2.39.1-1.el9.noarch.rpm perl-Git-SVN-2.39.1-1.el9.noarch.rpm ppc64le: git-2.39.1-1.el9.ppc64le.rpm git-core-2.39.1-1.el9.ppc64le.rpm git-core-debuginfo-2.39.1-1.el9.ppc64le.rpm git-credential-libsecret-2.39.1-1.el9.ppc64le.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.ppc64le.rpm git-daemon-2.39.1-1.el9.ppc64le.rpm git-daemon-debuginfo-2.39.1-1.el9.ppc64le.rpm git-debuginfo-2.39.1-1.el9.ppc64le.rpm git-debugsource-2.39.1-1.el9.ppc64le.rpm git-subtree-2.39.1-1.el9.ppc64le.rpm s390x: git-2.39.1-1.el9.s390x.rpm git-core-2.39.1-1.el9.s390x.rpm git-core-debuginfo-2.39.1-1.el9.s390x.rpm git-credential-libsecret-2.39.1-1.el9.s390x.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.s390x.rpm git-daemon-2.39.1-1.el9.s390x.rpm git-daemon-debuginfo-2.39.1-1.el9.s390x.rpm git-debuginfo-2.39.1-1.el9.s390x.rpm git-debugsource-2.39.1-1.el9.s390x.rpm git-subtree-2.39.1-1.el9.s390x.rpm x86_64: git-2.39.1-1.el9.x86_64.rpm git-core-2.39.1-1.el9.x86_64.rpm git-core-debuginfo-2.39.1-1.el9.x86_64.rpm git-credential-libsecret-2.39.1-1.el9.x86_64.rpm git-credential-libsecret-debuginfo-2.39.1-1.el9.x86_64.rpm git-daemon-2.39.1-1.el9.x86_64.rpm git-daemon-debuginfo-2.39.1-1.el9.x86_64.rpm git-debuginfo-2.39.1-1.el9.x86_64.rpm git-debugsource-2.39.1-1.el9.x86_64.rpm git-subtree-2.39.1-1.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-24765 https://access.redhat.com/security/cve/CVE-2022-29187 https://access.redhat.com/security/cve/CVE-2022-39253 https://access.redhat.com/security/cve/CVE-2022-39260 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZFo03tzjgjWX9erEAQhYSg//bKkon2hHN6jSsXXntqw9ViT5zo9r/KTD cV+t7GM4ipVK8j4EW8EnQKrJBWAzsEhqM2vh9MvM/PpTQ2I/JP53YbTed0qgxE3T SU07XMVbh1BA7OKyJ+eKfWJLBT03/VzzaepqQPwyHyFDAegJ/L9DlZOkHc9NJrfa R+N2Hde/TmUlnRl737ltWtQHE1QSTV1PQZuXb3AEWm6FDe7O62F0GpsuIWj1z8oo IIDLHRjp/mCqT6/A70NIRQvcwhLfRYYMOezKL80iGi7WwRokwEScDFE+gzB9FLrf pjNBFZkQVVxMVYOejArmPuLINaEdZJo/HAOiEtw9gOTzALyKFbWwOHDmSzz1hgbz kqFtZgwnpVZNs3UubXCgWeP4aU9xueZeyBHKNQKVERODtrKFt5jbpPrXu6qGyP9O 6GSgMbUDO5OMqOhTKQiMbKj5gO2DfOIO6vNP5eFwvSXPJG0ZlPIzAJD1cwZdtsVK wWBIMfjjc8zUh8OYm+CWg/lgpZLkQxe/wtFcC7Pw1u7nkN95npMXM3O75R8xe1zg xsa+wzjCmVRwrO2gLnT7/NUkY3saShCvBD+A82trnasbVlI/49oiojZY1PI3CZtz afQDlfLvgygNkV3e5CGe5p9PILwmFbrpALV43dEz6eY+MbeuoE6I7ON8tYtmx4Ds hOpSLJjOLjE=YQQZ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: git security update Advisory ID: RHSA-2023:0978-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0978 Issue date: 2023-02-28 CVE Names: CVE-2022-23521 CVE-2022-41903 ==================================================================== 1. Summary: An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their officialrepositories, but also makes it possible for the user to work with no network connection. Security Fix(es): * git: gitattributes parsing integer overflow (CVE-2022-23521) * git: Heap overflow in `git archive`, `git log --format` leading to RCE (CVE-2022-41903) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2162055 - CVE-2022-23521 git: gitattributes parsing integer overflow 2162056 - CVE-2022-41903 git: Heap overflow in `git archive`, `git log --format` leading to RCE 6. Package List: Red Hat Enterprise Linux Client Optional (v. 7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: perl-Git-1.8.3.1-24.el7_9.noarch.rpm ppc64: git-1.8.3.1-24.el7_9.ppc64.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64.rpm ppc64le: git-1.8.3.1-24.el7_9.ppc64le.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64le.rpm s390x: git-1.8.3.1-24.el7_9.s390x.rpm git-debuginfo-1.8.3.1-24.el7_9.s390x.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm ppc64: git-daemon-1.8.3.1-24.el7_9.ppc64.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.ppc64.rpm git-svn-1.8.3.1-24.el7_9.ppc64.rpm ppc64le: git-daemon-1.8.3.1-24.el7_9.ppc64le.rpm git-debuginfo-1.8.3.1-24.el7_9.ppc64le.rpm git-gnome-keyring-1.8.3.1-24.el7_9.ppc64le.rpm git-svn-1.8.3.1-24.el7_9.ppc64le.rpm s390x: git-daemon-1.8.3.1-24.el7_9.s390x.rpm git-debuginfo-1.8.3.1-24.el7_9.s390x.rpm git-gnome-keyring-1.8.3.1-24.el7_9.s390x.rpm git-svn-1.8.3.1-24.el7_9.s390x.rpm x86_64: git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: git-1.8.3.1-24.el7_9.src.rpm noarch: perl-Git-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): noarch: emacs-git-1.8.3.1-24.el7_9.noarch.rpm emacs-git-el-1.8.3.1-24.el7_9.noarch.rpm git-all-1.8.3.1-24.el7_9.noarch.rpm git-bzr-1.8.3.1-24.el7_9.noarch.rpm git-cvs-1.8.3.1-24.el7_9.noarch.rpm git-email-1.8.3.1-24.el7_9.noarch.rpm git-gui-1.8.3.1-24.el7_9.noarch.rpm git-hg-1.8.3.1-24.el7_9.noarch.rpm git-instaweb-1.8.3.1-24.el7_9.noarch.rpm git-p4-1.8.3.1-24.el7_9.noarch.rpm gitk-1.8.3.1-24.el7_9.noarch.rpm gitweb-1.8.3.1-24.el7_9.noarch.rpm perl-Git-SVN-1.8.3.1-24.el7_9.noarch.rpm x86_64: git-daemon-1.8.3.1-24.el7_9.x86_64.rpm git-debuginfo-1.8.3.1-24.el7_9.x86_64.rpm git-gnome-keyring-1.8.3.1-24.el7_9.x86_64.rpm git-svn-1.8.3.1-24.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-23521 https://access.redhat.com/security/cve/CVE-2022-41903 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY/3ztdzjgjWX9erEAQgw4g//fI6hgVC3Ds7f4CigbDHZ3G6uJVNLgZCo ePiMQ7yQ7QB4UHxl7tUlPxA57z+SdAnSWYXMxE/Q38b8asujPfn+RC/nfRYuDkjy 03Wl5Jw2x7ctlcab+cX3s/qZ77u4HlUF3Hv0bTdMOF6U3CjLzU7kywPVzWzGid4o nDKE+NjehScG/UL6ZzkvaKQr7UQk8Uak7gpoCtMsiTWFkAxA9y3xbzBdnNL77PMK tYpIvbGCdP/NgIGvOi2iCTIbKQf+mza6EBJUWMzjstR766icUdzb0NSel9V3tP0s w25oR17hCUnkSXy3b/eWFccuodGahO4p/DBxVFfOwVk16q0BkAqm9r8TGqijuNhp EDsIfJzHDanCqQEUjjWiwxPNmgUtk6/kqp1A8Vrz0O0OaiTQrWw0LHbwosAj5t1+ Q5bA9F0iBsBqjxEchrUo5fOPtTV7KNjN5KHA8KQACgXZ+QaT5oCLcOGoxyJzLizO eYENky+YuqJbBMo71DsJXMK8ovCqRYKzFI6w3zW9As0imZK72O0jtJYkxeV7E2uw N16NG92J3vgn0sq2zb08uxhQY/6YFNd2RDPZB+i4Vx40jZu95gfVNihpD/O9b2dZ AUtORmrxTGmgQvR4/0kyuEAW3p94BxA0M0fS7NmH9qfq2HU8tJLoh09t2kM3dX5/ 7Pkb0u+dNFE=sL46 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.