CVE-2022-41903
Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive` via the `export-subst` gitattribute. When processing the padding operators, there is a integer overflow in `pretty.c::format_and_pad_commit()` where a `size_t` is stored improperly as an `int`, and then added as an offset to a `memcpy()`. This overflow can be triggered directly by a user running a command which invokes the commit formatting machinery (e.g., `git log --format=...`). It may also be triggered indirectly through git archive via the export-subst mechanism, which expands format specifiers inside of files within the repository during a git archive. This integer overflow can result in arbitrary heap writes, which may result in arbitrary code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. Users who are unable to upgrade should disable `git archive` in untrusted repositories. If you expose git archive via `git daemon`, disable it by running `git config --global daemon.uploadArch false`.
Weaknesses (CWE)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| git | git | < 2.30.7 (affected), >= 2.31.0, < 2.31.6 (affected), >= 2.32.0, < 2.32.5 (affected), >= 2.33.0, < 2.33.6 (affected), >= 2.34.0, < 2.34.6 (affected), >= 2.35.0, < 2.35.6 (affected), >= 2.36.0, < 2.36.4 (affected), >= 2.37.0, < 2.37.5 (affected), >= 2.38.0, < 2.38.3 (affected), = 2.39.0 (affected) |
References & Technical Advisories
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2022-09-30T16:38:28 |
| Published | 2023-01-17T22:17:16 |
| Last Updated | 2025-03-10T21:21:50 |
Community Chatter & Buzz