Configuration in libgit2 - CVE-2023-22742
Published: January 22, 2023 / Updated: February 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to missing certificate validation in libgit2, when compiled using the optional, included libssh2 backend. Prior versions of libgit2 require the caller to set the certificate_check field of libgit2's git_remote_callbacks structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack.
Affected software
Gentoo Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server Module
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
libgit2-24 (Ubuntu package)
libgit2-26 (Ubuntu package)
libgit2-26
libgit2-26-32bit-debuginfo
libgit2-26-32bit
libgit2-26-debuginfo
libgit2-devel
libgit2-debugsource
libgit2-debuginfo
libgit2
libgit2-28 (Ubuntu package)
libgit2-28-32bit
libgit2-28-32bit-debuginfo
libgit2-28
libgit2-28-debuginfo
libgit2-1.1 (Ubuntu package)
libgit2-1_3-32bit-debuginfo
libgit2-1_3-32bit
libgit2-1_3-debuginfo
libgit2-1_3
libgit2-1.5 (Ubuntu package)
dev-libs/libgit2
How to mitigate CVE-2023-22742
libgit2-24 (Ubuntu package) - update to Ubuntu Pro
libgit2-26 (Ubuntu package) - update to Ubuntu Pro
libgit2-26 - update to 0.26.8-150000.3.18.1
libgit2-26-32bit-debuginfo - update to 0.26.8-150000.3.18.1
libgit2-26-32bit - update to 0.26.8-150000.3.18.1
libgit2-26-debuginfo - update to 0.26.8-150000.3.18.1
libgit2-devel - update to 0.27.8-7
libgit2-debugsource - update to 0.27.8-7
libgit2-debuginfo - update to 0.27.8-7
libgit2 - update to 0.27.8-7
libgit2-28 (Ubuntu package) - update to 0.28.4+dfsg.1-2ubuntu0.1
libgit2-28-32bit - update to 0.28.4-150200.3.6.1
libgit2-devel - addressed in versions 0.28.4-150200.3.6.1, 1.3.0-150400.3.6.1
libgit2-debugsource - addressed in versions 0.28.4-150200.3.6.1, 1.3.0-150400.3.6.1
libgit2-28-32bit-debuginfo - update to 0.28.4-150200.3.6.1
libgit2-28 - update to 0.28.4-150200.3.6.1
libgit2-28-debuginfo - update to 0.28.4-150200.3.6.1
libgit2-1.1 (Ubuntu package) - update to 1.1.0+dfsg.1-4.1ubuntu0.1
libgit2-1_3-32bit-debuginfo - update to 1.3.0-150400.3.6.1
libgit2-1_3-32bit - update to 1.3.0-150400.3.6.1
libgit2-1_3-debuginfo - update to 1.3.0-150400.3.6.1
libgit2-1_3 - update to 1.3.0-150400.3.6.1
libgit2-1.5 (Ubuntu package) - update to 1.5.1+ds-1ubuntu1.1
dev-libs/libgit2 - update to 1.7.2