-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: git-lfs security and bug fix update Advisory ID: RHSA-2023:2866-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2866 Issue date: 2023-05-16 CVE Names: CVE-2022-2880 CVE-2022-41715 CVE-2022-41717 ==================================================================== 1. Summary: An update for git-lfs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): * golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880) * golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) * golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2132868 - CVE-2022-2880 golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters 2132872 - CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps 2139382 - Rebase git-lfs to 3.2 version [rhel-8.8] 2161274 - CVE-2022-41717 golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: git-lfs-3.2.0-2.el8.src.rpm aarch64: git-lfs-3.2.0-2.el8.aarch64.rpm git-lfs-debuginfo-3.2.0-2.el8.aarch64.rpm git-lfs-debugsource-3.2.0-2.el8.aarch64.rpm ppc64le: git-lfs-3.2.0-2.el8.ppc64le.rpm git-lfs-debuginfo-3.2.0-2.el8.ppc64le.rpm git-lfs-debugsource-3.2.0-2.el8.ppc64le.rpm s390x: git-lfs-3.2.0-2.el8.s390x.rpm git-lfs-debuginfo-3.2.0-2.el8.s390x.rpm git-lfs-debugsource-3.2.0-2.el8.s390x.rpm x86_64: git-lfs-3.2.0-2.el8.x86_64.rpm git-lfs-debuginfo-3.2.0-2.el8.x86_64.rpm git-lfs-debugsource-3.2.0-2.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-2880 https://access.redhat.com/security/cve/CVE-2022-41715 https://access.redhat.com/security/cve/CVE-2022-41717 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.8_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZGNwHdzjgjWX9erEAQjTEA/9HJXSuoNNFimxsJttQ553ClVZko+sSpOz nrM15DzbYZKUJAE6WG9GL1Ctowziv5Eehl/krw3eJXk9A05JDFDagwcqnejPyKtG 8tcG3UOB5giSA37jO9NfA1+ZGCGAS1ArG+Q834duN4NnN+376CLGoH0qYYguDeNz Np+sC0C22IdIkU11Ux7hLMENXTsyvWxtnG2CcLuDTU+gY2FtoO8uGEcPQwjT3oZk Gih+1sLQaZO9/9i2Ys2kqzBYLIZU0szEr4Y5Rv5mlC1G2HKYQHdrQwFdo4KaBCdi NRxow0dq8h33k/fIE+jDhhbYQy4wQl7bGfWrAocuLRLUg9t8De/TwNrD1xDZk6ce ndQfAFUOicS+B//3dFL7GBxRNkHjUT7R4nKFHVuiukyEU8iLc00+676R2O8XJEWU IvryeeitRGnsAjpjGtoa3SdrEFIVVAFK5xxr55A/Yh3Y+hMnl7F3P64Sy709F4X2 BZAiPoZQU+zecJEuMxQK21+vZqqw6l3CRmjTREaOM+r2Ca9SkOZ8oJ8jtZHE50cL sOvN7tZ4MAMVup0f9ZBzypEYfXx8gr90C3ud7h+oe9aAcyIeOsAa0opWpZ5/v6J9 IGodk3TedG9eCyIBY9ucJuiVxIylk0q3yqX7SbRZlmCI9n1cSk6TEIQrTthkNBTQ dO2DP5m33kk=lZrN -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce