Integer overflow in Git for Windows - CVE-2022-23521
Published: January 17, 2023 / Updated: February 15, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input when parsing the .gitattributes attributes. A remote attacker can trick the victim into cloning a specially crafted repository and execute arbitrary code on the system.
Affected software
IBM Cloud Pak for Watson AIOps
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
ObjectScale
cflinuxfs3
Cloud Pak for Network Automation
Platform Automation Toolkit
XtremIO X2
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
CentOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
Red Hat OpenShift GitOps
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git (Ubuntu package)
emacs-git-el
git
git-daemon
git-gnome-keyring
git-svn
emacs-git
git-all
git-bzr
git-cvs
git-email
git-gui
git-hg
git-instaweb
git-p4
gitk
gitweb
perl-Git
perl-Git-SVN
git (Red Hat package)
git-doc
git-svn-debuginfo
git-arch
git-web
git-debugsource
git-daemon-debuginfo
git-core-debuginfo
git-core
git-debuginfo
rh-git227-git (Red Hat package)
git-help
git (Debian package)
git-core-doc
git-subtree
git-credential-libsecret
git-credential-libsecret-debuginfo
git-credential-gnome-keyring-debuginfo
git-credential-gnome-keyring
dev-vcs/git
redhat-release-virtualization-host (Red Hat package)
Gitlab Community Edition
GitLab Enterprise Edition
Visual Studio
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat OpenShift Data Science
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2022-23521
ObjectScale - update to 1.3.0
Migration Toolkit for Containers - update to 1.7.8
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.4
Red Hat OpenShift Container Platform - addressed in versions 4.9.56, 4.10.52, 4.11.28, 4.11.29, 4.11.31, 4.12.4
OpenShift Logging - update to 5.4.11
Red Hat Migration Toolkit for Applications - update to 6.0.1
Gitlab Community Edition - addressed in versions 15.5.9, 15.6.6, 15.7.5
GitLab Enterprise Edition - addressed in versions 15.5.9, 15.6.6, 15.7.5
Visual Studio - addressed in versions 15.9.52, 16.11.24 16.11.33328.57, 17.0.19 17.0.33402.176, 17.2.13 17.2.33402.178, 17.4.5 17.4.33403.182
git (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:2.17.1-1ubuntu0.14, 1:2.17.1-1ubuntu0.15, 1:2.25.1-1ubuntu3.7, 1:2.25.1-1ubuntu3.8, 1:2.34.1-1ubuntu1.6, 1:2.37.2-1ubuntu1.2
cflinuxfs3 - update to 0.351.0
emacs-git-el - update to 1.8.3.1-24
git - addressed in versions 1.8.3.1-24, 2.31.1-3
git-daemon - addressed in versions 1.8.3.1-24, 2.31.1-3
git-gnome-keyring - update to 1.8.3.1-24
git-svn - addressed in versions 1.8.3.1-24, 2.31.1-3
emacs-git - update to 1.8.3.1-24
git-all - addressed in versions 1.8.3.1-24, 2.31.1-3
git-bzr - update to 1.8.3.1-24
git-cvs - update to 1.8.3.1-24
git-email - addressed in versions 1.8.3.1-24, 2.31.1-3
git-gui - addressed in versions 1.8.3.1-24, 2.31.1-3
git-hg - update to 1.8.3.1-24
git-instaweb - addressed in versions 1.8.3.1-24, 2.31.1-3
git-p4 - update to 1.8.3.1-24
gitk - addressed in versions 1.8.3.1-24, 2.31.1-3
gitweb - addressed in versions 1.8.3.1-24, 2.31.1-3
perl-Git - addressed in versions 1.8.3.1-24, 2.31.1-3
perl-Git-SVN - addressed in versions 1.8.3.1-24, 2.31.1-3
git (Red Hat package) - addressed in versions 1.8.3.1-24.el7_9, 2.18.4-2.el8_1, 2.18.4-3.el8_2, 2.27.0-3.el8_4, 2.31.1-3.el8_6, 2.31.1-3.el8_7, 2.31.1-3.el9_0, 2.31.1-3.el9_1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Red Hat OpenShift Data Science - update to 1.22.1
Cloud Pak for Network Automation - update to 2.4.5
git-email - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-doc - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-svn-debuginfo - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1
git-arch - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
gitk - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-web - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-svn - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-gui - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-debugsource - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-daemon-debuginfo - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-daemon - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-cvs - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-core-debuginfo - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-core - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git - addressed in versions 2.26.2-27.63.2, 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
git-debuginfo - addressed in versions 2.26.2-150000.44.1, 2.35.3-150300.10.21.1
rh-git227-git (Red Hat package) - update to 2.27.0-4.el7
gitk - update to 2.27.0-11
git-svn - update to 2.27.0-11
perl-Git-SVN - update to 2.27.0-11
git-web - update to 2.27.0-11
git-help - update to 2.27.0-11
git-gui - update to 2.27.0-11
git-email - update to 2.27.0-11
perl-Git - update to 2.27.0-11
git-daemon - update to 2.27.0-11
git-debugsource - update to 2.27.0-11
git-debuginfo - update to 2.27.0-11
git - update to 2.27.0-11
git (Debian package) - update to 1:2.30.2-1+deb11u1
git - addressed in versions 2.30.7, 2.35.6
git-core-doc - update to 2.31.1-3
git-subtree - update to 2.31.1-3
git-credential-libsecret - update to 2.31.1-3
git-core - update to 2.31.1-3
perl-Git - update to 2.35.3-150300.10.21.1
git-p4 - update to 2.35.3-150300.10.21.1
git-credential-libsecret-debuginfo - update to 2.35.3-150300.10.21.1
git-credential-libsecret - update to 2.35.3-150300.10.21.1
git-credential-gnome-keyring-debuginfo - update to 2.35.3-150300.10.21.1
git-credential-gnome-keyring - update to 2.35.3-150300.10.21.1
git - addressed in versions 2.38.3-1.78, 2.39.1-1
git - addressed in versions 2.39.1-1.fc36, 2.39.1-1.fc37
dev-vcs/git - update to 2.39.3
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.0
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-6.el8ev
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
XtremIO X2 - update to 6.4.1-11
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
External References
Related Security Bulletins
- Multiple vulnerabilities in Git for Windows
- Ubuntu update for git
- Slackware Linux update for git
- Multiple vulnerabilities in GitLab Community and Enterprise
- Ubuntu update for git
- SUSE update for git
- SUSE update for git
- SUSE update for git
- Amazon Linux AMI update for git
- Red Hat Enterprise Linux 9 update for git
- Red Hat Enterprise Linux 8 update for git
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for git
- Red Hat Software Collections update for rh-git227-git
- Red Hat Enterprise Linux 8.4 Extended Update Support update for git
- Ubuntu update for git
- Red Hat Enterprise Linux 8.6 Extended Update Support update for git
- Red Hat Enterprise Linux 9.0 Extended Update Support update for git
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Microsoft Visual Studio update for Git
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Red Hat Enterprise Linux 7 update for git
- OpenShift Container Platform 4.11 update for Golang
- Ubuntu update for git
- CentOS 7 update for git
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Integer overflow in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 update for redhat-release-virtualization-host and redhat-virtualization-host
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Red Hat OpenShift Data Science 1.22
- VMware Tanzu Platform Automation Toolkit update for Git
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Data Protection Central
- Fedora 36 update for git
- Fedora 37 update for git
- Debian update for git
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Gentoo update for Git
- openEuler update for git
- Amazon Linux AMI update for git
- Red Hat Enterprise Linux 8 update for git
- Anolis OS update for git
- Anolis OS update for git
- Multiple vulnerabilities in Dell ObjectScale