<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:08:16.283509+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002579</id>
    <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
    <updated>2026-10-03T04:08:16.602053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:0610</id>
    <title>ALSA-2023:0610 — Important: git security update</title>
    <updated>2026-10-03T04:08:16.602137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: git, AlmaLinux:8: git-all, AlmaLinux:8: git-core, AlmaLinux:8: git-core-doc, AlmaLinux:8: git-credential-libsecret, AlmaLinux:8: git-daemon, AlmaLinux:8: git-email, AlmaLinux:8: git-gui, AlmaLinux:8: git-instaweb, AlmaLinux:8: git-subtree and 5 more</p>
<p>Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.</p>
<p>Security Fix(es):</p>
<p>* git: gitattributes parsing integer overflow (CVE-2022-23521)
* git: Heap overflow in `git archive`, `git log --format` leading to RCE (CVE-2022-41903)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:0610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00609</id>
    <title>bdu:2023-00609</title>
    <updated>2026-10-03T04:08:16.602190+00:00</updated>
    <content>bdu:2023-00609</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00609"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-41903</id>
    <title>Withdrawn: BELL-CVE-2022-41903 — CVE-2022-41903 does not affect BellSoft software</title>
    <updated>2026-10-03T04:08:16.602206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-41903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0032</id>
    <title>certfr-2023-avi-0032 — De multiples vulnérabilités ont été découvertes dans GitLab. Certaines
d'entre elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T04:08:16.602220+00:00</updated>
    <content>certfr-2023-avi-0032</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-nz77046</id>
    <title>CLEANSTART-2026-NZ77046 — Git is distributed revision control system</title>
    <updated>2026-10-03T04:08:16.602234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: git</p>
<p>Security vulnerability affects the git package. Git is distributed revision control system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-nz77046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-221665</id>
    <title>EUVD-2026-221665</title>
    <updated>2026-10-03T04:08:16.602252+00:00</updated>
    <content>EUVD-2026-221665</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-221665"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41903</id>
    <title>fkie_cve-2022-41903</title>
    <updated>2026-10-03T04:08:16.602263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive` via the `export-subst` gitattribute. When processing the padding operators, there is a integer overflow in `pretty.c::format_and_pad_commit()` where a `size_t` is stored improperly as an `int`, and then added as an offset to a `memcpy()`. This overflow can be triggered directly by a user running a command which invokes the commit formatting machinery (e.g., `git log --format=...`). It may also be triggered indirectly through git archive via the export-subst mechanism, which expands format specifiers inside of files within the repository during a git archive. This integer overflow can result in arbitrary heap writes, which may result in arbitrary code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. Users who are unable to upgrade should disable `git archive` in untrusted repositories. If you expose git archive via `git daemon`, disable it by running `git config --global daemon.uploadArch false`.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-41903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-41903</id>
    <title>gsd-2022-41903</title>
    <updated>2026-10-03T04:08:16.602288+00:00</updated>
    <content>gsd-2022-41903</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-41903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-11</id>
    <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
    <updated>2026-10-03T04:08:16.602299+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.</p>
<p>This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-41903</id>
    <title>msrc_CVE-2022-41903 — Integer overflow in `git archive` `git log --format` leading to RCE in git</title>
    <updated>2026-10-03T04:08:16.602701+00:00</updated>
    <content>msrc_CVE-2022-41903</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-41903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1044</id>
    <title>OESA-2023-1044 — git security update</title>
    <updated>2026-10-03T04:08:16.602718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: git, openEuler:20.03-LTS-SP3: git, openEuler:22.03-LTS: git, openEuler:22.03-LTS-SP1: git</p>
<p>Git is a free and open source distributed version control system designed to handle everything from small to very large projects with speed and efficiency. Git is easy to learn and has a tiny footprint with lightning fast performance. It outclasses SCM tools like Subversion, CVS, Perforce, and ClearCase with features like cheap local branching, convenient staging areas, and multiple workflows.

Security Fix(es):

Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.gitattributes` file to the repository, which contains a set of file patterns and the attributes that should be set for paths matching this pattern. When parsing gitattributes, multiple integer overflows can occur when there is a huge number of path patterns, a huge number of attributes for a single pattern, or when the declared attribute names are huge. These overflows can be triggered via a crafted `.gitattributes` file that may be part of the commit history. Git silently splits lines longer than 2KB when parsing gitattributes from a file, but not when parsing them from the index. Consequentially, the failure mode depends on whether the file exists in the working tree, the index or both. This integer overflow can result in arbitrary heap reads and writes, which may result in remote code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advis…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12625-1</id>
    <title>openSUSE-SU-2024:12625-1 — git-2.39.1-1.1 on GA media</title>
    <updated>2026-10-03T04:08:16.602758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>git-2.39.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12625-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0596</id>
    <title>RHSA-2023:0596 — Red Hat Security Advisory: git security update</title>
    <updated>2026-10-03T04:08:16.602775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>git: gitattributes parsing integer overflow git: Heap overflow in `git archive`, `git log --format` leading to RCE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:0108-1</id>
    <title>SUSE-SU-2023:0108-1 — Security update for git</title>
    <updated>2026-10-03T04:08:16.602791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for git</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:0108-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41903</id>
    <title>UBUNTU-CVE-2022-41903</title>
    <updated>2026-10-03T04:08:16.602805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: git, Ubuntu:Pro:16.04:LTS: git, Ubuntu:18.04:LTS: git, Ubuntu:20.04:LTS: git, Ubuntu:22.04:LTS: git</p>
<p>Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive` via the `export-subst` gitattribute. When processing the padding operators, there is a integer overflow in `pretty.c::format_and_pad_commit()` where a `size_t` is stored improperly as an `int`, and then added as an offset to a `memcpy()`. This overflow can be triggered directly by a user running a command which invokes the commit formatting machinery (e.g., `git log --format=...`). It may also be triggered indirectly through git archive via the export-subst mechanism, which expands format specifiers inside of files within the repository during a git archive. This integer overflow can result in arbitrary heap writes, which may result in arbitrary code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. Users who are unable to upgrade should disable `git archive` in untrusted repositories. If you expose git archive via `git daemon`, disable it by running `git config --global daemon.uploadArch false`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0105</id>
    <title>WID-SEC-W-2023-0105 — GitLab und Git: Mehrere Schwachstellen ermöglichen Codeausführung</title>
    <updated>2026-10-03T04:08:16.602834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab und Git ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0105"/>
  </entry>
</feed>
