9.8
CVSSv3

CVE-2022-23521

Published: 17/01/2023 Updated: 26/01/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9

Vulnerability Summary

Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern. When parsing gitattributes, multiple integer overflows can occur when there is a huge number of path patterns, a huge number of attributes for a single pattern, or when the declared attribute names are huge. These overflows can be triggered via a crafted `.gitattributes` file that may be part of the commit history. Git silently splits lines longer than 2KB when parsing gitattributes from a file, but not when parsing them from the index. Consequentially, the failure mode depends on whether the file exists in the working tree, the index or both. This integer overflow can result in arbitrary heap reads and writes, which may result in remote code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. There are no known workarounds for this issue.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

git-scm git

git-scm git 2.39.0

Vendor Advisories

Debian Bug report logs - #1029114 git: CVE-2022-23521 CVE-2022-41903 Package: src:git; Maintainer for src:git is Jonathan Nieder <jrnieder@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 17 Jan 2023 21:24:04 UTC Severity: grave Tags: security, upstream Found in versions git/1:2390-1, g ...
Several security issues were fixed in Git ...
USN-5810-1 introduced a regression in Git ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 82 Advanced Update Support, Red Hat Enterprise Linux 82 Telecommuni ...
概要 Important: git security update タイプ/重大度 Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems トピック An update for git is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat Product Security has r ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security ...
Synopsis Important: rh-git227-git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-git227-git is now available for Red Hat Software CollectionsRed Hat Product Security has rated this updat ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat Product Security has ra ...
概要 Important: git security update タイプ/重大度 Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems トピック An update for git is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security has r ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security ...
Synopsis Moderate: OpenShift Container Platform 41129 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41129 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Moderate: OpenShift Container Platform 41131 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41131 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift C ...
Description<!---->A flaw was found in Git, a distributed revision control system When parsing gitattributes, a mechanism to allow defining attributes for paths, multiple integer overflows can occur when there is a huge number of path patterns, attributes for a single pattern, or declared attribute names These overflows can be triggered via a craf ...
Git is distributed revision control system gitattributes are a mechanism to allow defining attributes for paths These attributes can be defined by adding a `gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern When parsing gitattributes, multiple integ ...
Synopsis Moderate: Red Hat OpenShift (Logging Subsystem) security update Type/Severity Security Advisory: Moderate Topic Logging Subsystem 557 - Red Hat OpenShift Description Logging Subsystem 557 - Red Hat OpenShift Solution Before applying this update, make sure all previously released erratarelevant to your system have been applied ...
Synopsis Moderate: OpenShift Container Platform 41052 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41052 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Important: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift GitOps 16Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed sever ...
Synopsis Important: Red Hat OpenShift Data Science 1221 security update Type/Severity Security Advisory: Important Topic An update for kubeflow, dashboard, deployer is now available for Red Hat OpenShift Data Science 122Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Important: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift GitOps 17Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed sever ...
Synopsis Important: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift GitOps 15Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed sever ...
Git is distributed revision control system gitattributes are a mechanism to allow defining attributes for paths These attributes can be defined by adding a `gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern When parsing gitattributes, multiple integ ...
Synopsis Moderate: Red Hat OpenShift (Logging Subsystem) security update Type/Severity Security Advisory: Moderate Topic An update is now available for the Logging subsystem for Red Hat OpenShift 54Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: OpenShift Container Platform 41128 security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41128 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impac ...
Synopsis Moderate: OpenShift Container Platform 4124 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4124 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Moderate: Red Hat Advanced Cluster Management 264 bug fixes and security updates Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 264 GeneralAvailability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security ...
Synopsis Moderate: OpenShift Container Platform 4956 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4956 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Platf ...
Synopsis Important: Migration Toolkit for Applications security and bug fix update Type/Severity Security Advisory: Important Topic Migration Toolkit for Applications 601 releaseRed Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) base score, whichgives a detail ...

Github Repositories

git-crasher-poc-cve-2022-23521

CVE-2022-23521 Git is distributed revision control system gitattributes are a mechanism to allow defining attributes for paths These attributes can be defined by adding a gitattributes file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern When parsing gitattributes, multiple integer overflows can

rpmostree-update Wrapper of rpm-ostree update that compares previous update output Also outputs changelog with diff Still experimental Usage $ rpmostree-update Preview: 2 metadata, 0 content objects fetched; 52 KiB transferred in 3 seconds; 0 bytes content written Enabled rpm-md repositories: fedora-cisco-openh264 updates fedora updates-archive Updating metadata for 'fed