Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:3280 - Security Advisory
Issued:
2023-05-23
Updated:
2023-05-23

RHSA-2023:3280 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: rh-git227-git security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for rh-git227-git is now available for Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.

Security Fix(es):

  • git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (CVE-2023-25652)
  • git: arbitrary configuration injection when renaming or deleting a section from a configuration file (CVE-2023-29007)
  • git: malicious placement of crafted messages when git was compiled with runtime prefix (CVE-2023-25815)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Software Collections (for RHEL Server) 1 for RHEL 7 x86_64
  • Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7 s390x
  • Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7 ppc64le
  • Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7 x86_64

Fixes

  • BZ - 2188333 - CVE-2023-25652 git: by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents
  • BZ - 2188337 - CVE-2023-25815 git: malicious placement of crafted messages when git was compiled with runtime prefix
  • BZ - 2188338 - CVE-2023-29007 git: arbitrary configuration injection when renaming or deleting a section from a configuration file

CVEs

  • CVE-2023-25652
  • CVE-2023-25815
  • CVE-2023-29007

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Software Collections (for RHEL Server) 1 for RHEL 7

SRPM
rh-git227-git-2.27.0-6.el7.src.rpm SHA-256: d35841710b82c479851ab65d3793e73678ab928aa40acf925e16f18391465d73
x86_64
rh-git227-git-2.27.0-6.el7.x86_64.rpm SHA-256: 62050e157bc6d11de02f09d42583fef67ba1dfb00b49232355a9e227c927664b
rh-git227-git-all-2.27.0-6.el7.noarch.rpm SHA-256: 7142fd857ddb62bb77920941c6e2ddbdacab5d21176d978894a56d7412b6694b
rh-git227-git-core-2.27.0-6.el7.x86_64.rpm SHA-256: 184ee77515c232620d513cbe1320339e6b0ef8df17a2bf3c13af83b4fc4eb9f9
rh-git227-git-core-doc-2.27.0-6.el7.noarch.rpm SHA-256: b962f7e149351ffc9929c2d754c8385d087514bbd946ed88562a1d88ce50ee73
rh-git227-git-credential-libsecret-2.27.0-6.el7.x86_64.rpm SHA-256: bfca589082b3e8f2fcfa760f0226917131eeeda8fe862e02ea06b1ed41832d66
rh-git227-git-cvs-2.27.0-6.el7.noarch.rpm SHA-256: e03b2477b364d9af8dcab8e5ce73df09f161055fe8ffdf5ecdedf57a57bbd2dd
rh-git227-git-daemon-2.27.0-6.el7.x86_64.rpm SHA-256: f13898df8e1c9bbd8e142fb599e16ec41e7bf8ac04e1406cf1ff45934b5487f5
rh-git227-git-debuginfo-2.27.0-6.el7.x86_64.rpm SHA-256: d63cd63214e06822a80d87a6a76320164ce3c7e634b1f59b2e92a0e807b640ef
rh-git227-git-email-2.27.0-6.el7.noarch.rpm SHA-256: 8d499777314e5fc038007e2ea1e64c412dd5410bb7984fa2934c89ff8c401edd
rh-git227-git-gui-2.27.0-6.el7.noarch.rpm SHA-256: 5f00ee29790f9bc583a69305077706e26fe2ab58e6a6f35c3b82c4153119b9b1
rh-git227-git-instaweb-2.27.0-6.el7.noarch.rpm SHA-256: 211edcd288588c44311b36d7ed416a2a7a163a107bd8a68ca492102c8fd408c5
rh-git227-git-p4-2.27.0-6.el7.noarch.rpm SHA-256: a4b779919ef42b30d6ec343188b0113b5f0ef38ed5751d9f3cb0d81def055d56
rh-git227-git-subtree-2.27.0-6.el7.x86_64.rpm SHA-256: 74e41341b8d25b64976196f27799d4cd0cb06696d49fa0cdd4ec639cf7223bbe
rh-git227-git-svn-2.27.0-6.el7.noarch.rpm SHA-256: 7471a5fc09cecd809615741c04dd33f1b4cec69e1e0975e4368862baf86b0675
rh-git227-gitk-2.27.0-6.el7.noarch.rpm SHA-256: a7aeed87972839e272edb9941ef0193fb456707a98ef33e2c1a3bb2c876668fb
rh-git227-gitweb-2.27.0-6.el7.noarch.rpm SHA-256: 628cf7e6c5d01d5a183e2ebeabf268cbefa90c438990ac614a7688da5693d33a
rh-git227-perl-Git-2.27.0-6.el7.noarch.rpm SHA-256: 35b2fe1a902567bdb48e8f990a6d8bac786d92e990c66abae57e3c4d83c6659a
rh-git227-perl-Git-SVN-2.27.0-6.el7.noarch.rpm SHA-256: 1817d23d50ce0364ecee9d9efdb0c6f9d80727486e1ffa1e802f9fed6def3dc5

Red Hat Software Collections (for RHEL Server for System Z) 1 for RHEL 7

SRPM
rh-git227-git-2.27.0-6.el7.src.rpm SHA-256: d35841710b82c479851ab65d3793e73678ab928aa40acf925e16f18391465d73
s390x
rh-git227-git-2.27.0-6.el7.s390x.rpm SHA-256: 0926adcac8744c9d4781e3e6dc0334889acb7edcfb8c14a599bb80956de85a28
rh-git227-git-all-2.27.0-6.el7.noarch.rpm SHA-256: 7142fd857ddb62bb77920941c6e2ddbdacab5d21176d978894a56d7412b6694b
rh-git227-git-core-2.27.0-6.el7.s390x.rpm SHA-256: 0f6d5f7635a340b5b286b37680c1a6330f5f1e7c58f695721b3651bee2f931e2
rh-git227-git-core-doc-2.27.0-6.el7.noarch.rpm SHA-256: b962f7e149351ffc9929c2d754c8385d087514bbd946ed88562a1d88ce50ee73
rh-git227-git-credential-libsecret-2.27.0-6.el7.s390x.rpm SHA-256: 3ad48ff3ea89008a70e5d8883dcf3bbcc31e468f24865b485f2d533ac8ef46f3
rh-git227-git-cvs-2.27.0-6.el7.noarch.rpm SHA-256: e03b2477b364d9af8dcab8e5ce73df09f161055fe8ffdf5ecdedf57a57bbd2dd
rh-git227-git-daemon-2.27.0-6.el7.s390x.rpm SHA-256: e9c605e3b2bd40f376879c05e8843a9c313bf75fecfbbfc6f33348a799b89bf2
rh-git227-git-debuginfo-2.27.0-6.el7.s390x.rpm SHA-256: aa3d85223bfe3aa9a5e1ab779ad038becd4698358ab989707098476310680138
rh-git227-git-email-2.27.0-6.el7.noarch.rpm SHA-256: 8d499777314e5fc038007e2ea1e64c412dd5410bb7984fa2934c89ff8c401edd
rh-git227-git-gui-2.27.0-6.el7.noarch.rpm SHA-256: 5f00ee29790f9bc583a69305077706e26fe2ab58e6a6f35c3b82c4153119b9b1
rh-git227-git-instaweb-2.27.0-6.el7.noarch.rpm SHA-256: 211edcd288588c44311b36d7ed416a2a7a163a107bd8a68ca492102c8fd408c5
rh-git227-git-p4-2.27.0-6.el7.noarch.rpm SHA-256: a4b779919ef42b30d6ec343188b0113b5f0ef38ed5751d9f3cb0d81def055d56
rh-git227-git-subtree-2.27.0-6.el7.s390x.rpm SHA-256: 602df64e606cf13f83cd5e34bd87358dd61f47285915716746e8697cd585adf2
rh-git227-git-svn-2.27.0-6.el7.noarch.rpm SHA-256: 7471a5fc09cecd809615741c04dd33f1b4cec69e1e0975e4368862baf86b0675
rh-git227-gitk-2.27.0-6.el7.noarch.rpm SHA-256: a7aeed87972839e272edb9941ef0193fb456707a98ef33e2c1a3bb2c876668fb
rh-git227-gitweb-2.27.0-6.el7.noarch.rpm SHA-256: 628cf7e6c5d01d5a183e2ebeabf268cbefa90c438990ac614a7688da5693d33a
rh-git227-perl-Git-2.27.0-6.el7.noarch.rpm SHA-256: 35b2fe1a902567bdb48e8f990a6d8bac786d92e990c66abae57e3c4d83c6659a
rh-git227-perl-Git-SVN-2.27.0-6.el7.noarch.rpm SHA-256: 1817d23d50ce0364ecee9d9efdb0c6f9d80727486e1ffa1e802f9fed6def3dc5

Red Hat Software Collections (for RHEL Server for IBM Power LE) 1 for RHEL 7

SRPM
rh-git227-git-2.27.0-6.el7.src.rpm SHA-256: d35841710b82c479851ab65d3793e73678ab928aa40acf925e16f18391465d73
ppc64le
rh-git227-git-2.27.0-6.el7.ppc64le.rpm SHA-256: d85071acb33ced80e08bad9d0fbe02be4b616589b6ca733d2186bb2a8dfd5609
rh-git227-git-all-2.27.0-6.el7.noarch.rpm SHA-256: 7142fd857ddb62bb77920941c6e2ddbdacab5d21176d978894a56d7412b6694b
rh-git227-git-core-2.27.0-6.el7.ppc64le.rpm SHA-256: 1d3173ac576ce19c1ef5197a0a228e23c5e477b517fe72e146719a15431b9e86
rh-git227-git-core-doc-2.27.0-6.el7.noarch.rpm SHA-256: b962f7e149351ffc9929c2d754c8385d087514bbd946ed88562a1d88ce50ee73
rh-git227-git-credential-libsecret-2.27.0-6.el7.ppc64le.rpm SHA-256: 404b78a2fa92075cad9f9e31181b9958cccd0c6a7feb70d1be8f5cf13926d1c9
rh-git227-git-cvs-2.27.0-6.el7.noarch.rpm SHA-256: e03b2477b364d9af8dcab8e5ce73df09f161055fe8ffdf5ecdedf57a57bbd2dd
rh-git227-git-daemon-2.27.0-6.el7.ppc64le.rpm SHA-256: f8e511e5e845efd806bf069cc8ed5c8451ce3bc8aeda7c292d98a9675f19c09d
rh-git227-git-debuginfo-2.27.0-6.el7.ppc64le.rpm SHA-256: 0fb427ad9c20579f5eb2f6b267f41c0bd38ecaa7c7f385d361f53d4cc9153644
rh-git227-git-email-2.27.0-6.el7.noarch.rpm SHA-256: 8d499777314e5fc038007e2ea1e64c412dd5410bb7984fa2934c89ff8c401edd
rh-git227-git-gui-2.27.0-6.el7.noarch.rpm SHA-256: 5f00ee29790f9bc583a69305077706e26fe2ab58e6a6f35c3b82c4153119b9b1
rh-git227-git-instaweb-2.27.0-6.el7.noarch.rpm SHA-256: 211edcd288588c44311b36d7ed416a2a7a163a107bd8a68ca492102c8fd408c5
rh-git227-git-p4-2.27.0-6.el7.noarch.rpm SHA-256: a4b779919ef42b30d6ec343188b0113b5f0ef38ed5751d9f3cb0d81def055d56
rh-git227-git-subtree-2.27.0-6.el7.ppc64le.rpm SHA-256: 5c992ca15835a086baa3e34ea29606dff83644ba0097adde951cf230cda2b91d
rh-git227-git-svn-2.27.0-6.el7.noarch.rpm SHA-256: 7471a5fc09cecd809615741c04dd33f1b4cec69e1e0975e4368862baf86b0675
rh-git227-gitk-2.27.0-6.el7.noarch.rpm SHA-256: a7aeed87972839e272edb9941ef0193fb456707a98ef33e2c1a3bb2c876668fb
rh-git227-gitweb-2.27.0-6.el7.noarch.rpm SHA-256: 628cf7e6c5d01d5a183e2ebeabf268cbefa90c438990ac614a7688da5693d33a
rh-git227-perl-Git-2.27.0-6.el7.noarch.rpm SHA-256: 35b2fe1a902567bdb48e8f990a6d8bac786d92e990c66abae57e3c4d83c6659a
rh-git227-perl-Git-SVN-2.27.0-6.el7.noarch.rpm SHA-256: 1817d23d50ce0364ecee9d9efdb0c6f9d80727486e1ffa1e802f9fed6def3dc5

Red Hat Software Collections (for RHEL Workstation) 1 for RHEL 7

SRPM
rh-git227-git-2.27.0-6.el7.src.rpm SHA-256: d35841710b82c479851ab65d3793e73678ab928aa40acf925e16f18391465d73
x86_64
rh-git227-git-2.27.0-6.el7.x86_64.rpm SHA-256: 62050e157bc6d11de02f09d42583fef67ba1dfb00b49232355a9e227c927664b
rh-git227-git-all-2.27.0-6.el7.noarch.rpm SHA-256: 7142fd857ddb62bb77920941c6e2ddbdacab5d21176d978894a56d7412b6694b
rh-git227-git-core-2.27.0-6.el7.x86_64.rpm SHA-256: 184ee77515c232620d513cbe1320339e6b0ef8df17a2bf3c13af83b4fc4eb9f9
rh-git227-git-core-doc-2.27.0-6.el7.noarch.rpm SHA-256: b962f7e149351ffc9929c2d754c8385d087514bbd946ed88562a1d88ce50ee73
rh-git227-git-credential-libsecret-2.27.0-6.el7.x86_64.rpm SHA-256: bfca589082b3e8f2fcfa760f0226917131eeeda8fe862e02ea06b1ed41832d66
rh-git227-git-cvs-2.27.0-6.el7.noarch.rpm SHA-256: e03b2477b364d9af8dcab8e5ce73df09f161055fe8ffdf5ecdedf57a57bbd2dd
rh-git227-git-daemon-2.27.0-6.el7.x86_64.rpm SHA-256: f13898df8e1c9bbd8e142fb599e16ec41e7bf8ac04e1406cf1ff45934b5487f5
rh-git227-git-debuginfo-2.27.0-6.el7.x86_64.rpm SHA-256: d63cd63214e06822a80d87a6a76320164ce3c7e634b1f59b2e92a0e807b640ef
rh-git227-git-email-2.27.0-6.el7.noarch.rpm SHA-256: 8d499777314e5fc038007e2ea1e64c412dd5410bb7984fa2934c89ff8c401edd
rh-git227-git-gui-2.27.0-6.el7.noarch.rpm SHA-256: 5f00ee29790f9bc583a69305077706e26fe2ab58e6a6f35c3b82c4153119b9b1
rh-git227-git-instaweb-2.27.0-6.el7.noarch.rpm SHA-256: 211edcd288588c44311b36d7ed416a2a7a163a107bd8a68ca492102c8fd408c5
rh-git227-git-p4-2.27.0-6.el7.noarch.rpm SHA-256: a4b779919ef42b30d6ec343188b0113b5f0ef38ed5751d9f3cb0d81def055d56
rh-git227-git-subtree-2.27.0-6.el7.x86_64.rpm SHA-256: 74e41341b8d25b64976196f27799d4cd0cb06696d49fa0cdd4ec639cf7223bbe
rh-git227-git-svn-2.27.0-6.el7.noarch.rpm SHA-256: 7471a5fc09cecd809615741c04dd33f1b4cec69e1e0975e4368862baf86b0675
rh-git227-gitk-2.27.0-6.el7.noarch.rpm SHA-256: a7aeed87972839e272edb9941ef0193fb456707a98ef33e2c1a3bb2c876668fb
rh-git227-gitweb-2.27.0-6.el7.noarch.rpm SHA-256: 628cf7e6c5d01d5a183e2ebeabf268cbefa90c438990ac614a7688da5693d33a
rh-git227-perl-Git-2.27.0-6.el7.noarch.rpm SHA-256: 35b2fe1a902567bdb48e8f990a6d8bac786d92e990c66abae57e3c4d83c6659a
rh-git227-perl-Git-SVN-2.27.0-6.el7.noarch.rpm SHA-256: 1817d23d50ce0364ecee9d9efdb0c6f9d80727486e1ffa1e802f9fed6def3dc5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility