9.8
CVSSv3

CVE-2022-23521

Published: 17/01/2023 Updated: 27/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern. When parsing gitattributes, multiple integer overflows can occur when there is a huge number of path patterns, a huge number of attributes for a single pattern, or when the declared attribute names are huge. These overflows can be triggered via a crafted `.gitattributes` file that may be part of the commit history. Git silently splits lines longer than 2KB when parsing gitattributes from a file, but not when parsing them from the index. Consequentially, the failure mode depends on whether the file exists in the working tree, the index or both. This integer overflow can result in arbitrary heap reads and writes, which may result in remote code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. There are no known workarounds for this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

git-scm git

git-scm git 2.39.0

Vendor Advisories

Debian Bug report logs - #1029114 git: CVE-2022-23521 CVE-2022-41903 Package: src:git; Maintainer for src:git is Jonathan Nieder <jrnieder@gmailcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 17 Jan 2023 21:24:04 UTC Severity: grave Tags: security, upstream Found in versions git/1:2390-1, g ...
USN-5810-1 introduced a regression in Git ...
Several security issues were fixed in Git ...
Git is distributed revision control system gitattributes are a mechanism to allow defining attributes for paths These attributes can be defined by adding a `gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern When parsing gitattributes, multiple integ ...
Git is distributed revision control system gitattributes are a mechanism to allow defining attributes for paths These attributes can be defined by adding a `gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern When parsing gitattributes, multiple integ ...
Description<!---->A flaw was found in Git, a distributed revision control system When parsing gitattributes, a mechanism to allow defining attributes for paths, multiple integer overflows can occur when there is a huge number of path patterns, attributes for a single pattern, or declared attribute names These overflows can be triggered via a craf ...
Synopsis Moderate: Red Hat OpenShift (Logging Subsystem) security update Type/Severity Security Advisory: Moderate Topic Logging Subsystem 557 - Red Hat OpenShift Description Logging Subsystem 557 - Red Hat OpenShift Solution Before applying this update, make sure all previously released erratarelevant to your system have been applied ...
概要 Important: git security update タイプ/重大度 Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems トピック An update for git is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat Product Security has r ...
Synopsis Important: OpenShift Container Platform 41128 security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41128 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impac ...
概要 Important: git security update タイプ/重大度 Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems トピック An update for git is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security has r ...
Synopsis Moderate: OpenShift Container Platform 41131 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41131 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift C ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat Product Security has ra ...
Synopsis Important: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift GitOps 15Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed sever ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security ...
Synopsis Important: rh-git227-git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-git227-git is now available for Red Hat Software CollectionsRed Hat Product Security has rated this updat ...
Synopsis Moderate: OpenShift Container Platform 4956 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4956 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Platf ...
Synopsis Important: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift GitOps 17Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed sever ...
Synopsis Important: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift GitOps 16Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed sever ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security ...
Synopsis Moderate: OpenShift Container Platform 41129 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41129 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security ...
Synopsis Important: Red Hat OpenShift Data Science 1221 security update Type/Severity Security Advisory: Important Topic An update for kubeflow, dashboard, deployer is now available for Red Hat OpenShift Data Science 122Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Moderate: Red Hat Advanced Cluster Management 264 bug fixes and security updates Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 264 GeneralAvailability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security ...
Synopsis Moderate: OpenShift Container Platform 41052 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41052 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Moderate: Red Hat OpenShift (Logging Subsystem) security update Type/Severity Security Advisory: Moderate Topic An update is now available for the Logging subsystem for Red Hat OpenShift 54Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Important: git security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for git is now available for Red Hat Enterprise Linux 82 Advanced Update Support, Red Hat Enterprise Linux 82 Telecommuni ...
Synopsis Moderate: OpenShift Container Platform 4124 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4124 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: Migration Toolkit for Applications security and bug fix update Type/Severity Security Advisory: Important Topic Migration Toolkit for Applications 601 releaseRed Hat Product Security has rated this update as having a security impactof Important A Common Vulnerability Scoring System (CVSS) base score, whichgives a detail ...
ALAS-2023-282 Amazon Linux 2022 Security Advisory: ALAS-2023-282 Advisory Release Date: 2023-01-31 21:11 Pacific Advisory Updated Date: 2023-01-31 21:11 Pac ...

Github Repositories

vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional, Windows-specific issue known as CVE-2022-41953.

DESCRIPTION vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 239 and older Git for Windows was also patched to address an additional, Windows-specific issue known as CVE-2022-41953 These scripts: build distribution containers and installs the git version provided displays the version NOTE The building of git on Gentoo takes a long time Be patient