← Back to browse · API

CVE-2022-41903

Severity
CRITICAL
CVSS
9.8
EPSS
0.44268
Risk score
54.69
CISA KEV
No
PoC
No
Published
2023-01-17
Modified
2025-03-10
First seen
2026-08-07
Aliases
EUVD-2022-45041
Products
git-for-windows:Git 2.31.0, < 2.31.6, git-for-windows:Git 2.32.0, < 2.32.5, git-for-windows:Git 2.33.0, < 2.33.6, git-for-windows:Git 2.34.0, < 2.34.6, git-for-windows:Git 2.35.0, < 2.35.6, git-for-windows:Git 2.36.0, < 2.36.4, git-for-windows:Git 2.37.0, < 2.37.5, git-for-windows:Git 2.38.0, < 2.38.3, git-for-windows:Git < 2.30.7, git-for-windows:Git = 2.39.0
Sources
euvd EUVD-2022-45041

Description

Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exposed to `git archive` via the `export-subst` gitattribute. When processing the padding operators, there is a integer overflow in `pretty.c::format_and_pad_commit()` where a `size_t` is stored improperly as an `int`, and then added as an offset to a `memcpy()`. This overflow can be triggered directly by a user running a command which invokes the commit formatting machinery (e.g., `git log --format=...`). It may also be triggered indirectly through git archive via the export-subst mechanism, which expands format specifiers inside of files within the repository during a git archive. This integer overflow can result in arbitrary heap writes, which may result in arbitrary code execution. The problem has been patched in the versions published on 2023-01-17, going back to v2.30.7. Users are advised to upgrade. Users who are unable to upgrade should disable `git archive` in untrusted repositories. If you expose git archive via `git daemon`, disable it by running `git config --global daemon.uploadArch false`.

References