Lucene search

K
redhatRedHatRHSA-2023:2866
HistoryMay 16, 2023 - 5:56 a.m.

(RHSA-2023:2866) Moderate: git-lfs security and bug fix update

2023-05-1605:56:48
access.redhat.com
46
git large file storage
security fix
golang
red hat enterprise linux 8.8
cve-2022-2880
cve-2022-41715
cve-2022-41717
cvss score
acknowledgments
remote server
http/2 requests
release notes

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.0%

Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):

  • golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)

  • golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)

  • golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.8 Release Notes linked from the References section.