Heap-based buffer overflow in Git for Windows - CVE-2022-41903

 

Heap-based buffer overflow in Git for Windows - CVE-2022-41903

Published: January 17, 2023


Vulnerability identifier: #VU71238
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41903
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error during git archive invocation. A remote attacker can trick the victim into using the application against a specially crafted archive, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Git for Windows
IBM Cloud Pak for Watson AIOps
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
ObjectScale
cflinuxfs3
Cloud Pak for Network Automation
Platform Automation Toolkit
XtremIO X2
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
Red Hat OpenShift GitOps
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git (Ubuntu package)
emacs-git-el
git
git-daemon
git-gnome-keyring
git-svn
emacs-git
git-all
git-bzr
git-cvs
git-email
git-gui
git-hg
perl-Git-SVN
git-instaweb
git-p4
perl-Git
gitweb
gitk
git (Red Hat package)
git-daemon-debuginfo
git-core
git-core-debuginfo
git-doc
git-svn-debuginfo
git-arch
git-web
git-debugsource
git-debuginfo
rh-git227-git (Red Hat package)
git-help
git (Debian package)
git-core-doc
git-subtree
git-credential-libsecret
git-credential-libsecret-debuginfo
git-credential-gnome-keyring-debuginfo
git-credential-gnome-keyring
dev-vcs/git
redhat-release-virtualization-host (Red Hat package)
Gitlab Community Edition
GitLab Enterprise Edition
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat OpenShift Data Science
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM

How to mitigate CVE-2022-41903

Install updates from vendor's website.

Git for Windows - addressed in versions 2.35.6.1, 2.39.1.1
ObjectScale - update to 1.3.0
Migration Toolkit for Containers - update to 1.7.8
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.4
Red Hat OpenShift Container Platform - addressed in versions 4.9.56, 4.10.52, 4.11.28, 4.11.29, 4.11.31, 4.12.4
OpenShift Logging - update to 5.4.11
Red Hat Migration Toolkit for Applications - update to 6.0.1
Gitlab Community Edition - addressed in versions 15.5.9, 15.6.6, 15.7.5
GitLab Enterprise Edition - addressed in versions 15.5.9, 15.6.6, 15.7.5
git (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.17.1-1ubuntu0.14, 1:2.17.1-1ubuntu0.15, 1:2.25.1-1ubuntu3.7, 1:2.25.1-1ubuntu3.8, 1:2.34.1-1ubuntu1.6, 1:2.37.2-1ubuntu1.2
cflinuxfs3 - update to 0.351.0
emacs-git-el - update to 1.8.3.1-24
git - addressed in versions 1.8.3.1-24, 2.31.1-3
git-daemon - addressed in versions 1.8.3.1-24, 2.31.1-3
git-gnome-keyring - update to 1.8.3.1-24
git-svn - addressed in versions 1.8.3.1-24, 2.31.1-3
emacs-git - update to 1.8.3.1-24
git-all - addressed in versions 1.8.3.1-24, 2.31.1-3
git-bzr - update to 1.8.3.1-24
git-cvs - update to 1.8.3.1-24
git-email - addressed in versions 1.8.3.1-24, 2.31.1-3
git-gui - addressed in versions 1.8.3.1-24, 2.31.1-3
git-hg - update to 1.8.3.1-24
perl-Git-SVN - addressed in versions 1.8.3.1-24, 2.31.1-3
git-instaweb - addressed in versions 1.8.3.1-24, 2.31.1-3
git-p4 - update to 1.8.3.1-24
perl-Git - addressed in versions 1.8.3.1-24, 2.31.1-3
gitweb - addressed in versions 1.8.3.1-24, 2.31.1-3
gitk - addressed in versions 1.8.3.1-24, 2.31.1-3
git (Red Hat package) - addressed in versions 1.8.3.1-24.el7_9, 2.18.4-2.el8_1, 2.18.4-3.el8_2, 2.27.0-3.el8_4, 2.31.1-3.el8_6, 2.31.1-3.el8_7, 2.31.1-3.el9_0, 2.31.1-3.el9_1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Red Hat OpenShift Data Science - update to 1.22.1
Cloud Pak for Network Automation - update to 2.4.5
git-daemon-debuginfo - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-core - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-core-debuginfo - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-cvs - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-daemon - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-doc - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-svn-debuginfo - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1
git-arch - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
gitk - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-web - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-svn - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-gui - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-email - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-debugsource - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-debuginfo - addressed in versions 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
rh-git227-git (Red Hat package) - update to 2.27.0-4.el7
git - update to 2.27.0-11
git-gui - update to 2.27.0-11
git-help - update to 2.27.0-11
git-debuginfo - update to 2.27.0-11
git-daemon - update to 2.27.0-11
git-email - update to 2.27.0-11
git-web - update to 2.27.0-11
git-svn - update to 2.27.0-11
perl-Git - update to 2.27.0-11
perl-Git-SVN - update to 2.27.0-11
gitk - update to 2.27.0-11
git-debugsource - update to 2.27.0-11
git (Debian package) - update to 1:2.30.2-1+deb11u1
git - addressed in versions 2.30.7, 2.35.6
git-core - update to 2.31.1-3
git-core-doc - update to 2.31.1-3
git-subtree - update to 2.31.1-3
git-credential-libsecret - update to 2.31.1-3
perl-Git - update to 2.35.3-150300.10.21.1
git-p4 - update to 2.35.3-150300.10.21.1
git-credential-libsecret-debuginfo - update to 2.35.3-150300.10.21.1
git-credential-libsecret - update to 2.35.3-150300.10.21.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.21.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.21.1
git - addressed in versions 2.38.3-1.78, 2.39.1-1
git - addressed in versions 2.39.1-1.fc36, 2.39.1-1.fc37
dev-vcs/git - update to 2.39.3
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.0
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-6.el8ev
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
XtremIO X2 - update to 6.4.1-11
IBM Qradar SIEM - update to 7.5.0 Update Pack 6

External References

Related Security Bulletins