/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/vuln_list_record.csv
101 строка566 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
alma
alma/10/2025/ALSA-2025:10140.json
CVE-2025-4330
ALSA-2025:10140
python-unversioned-command
Important
3.12.9-2.el10_0.2
< 3.12.9-2.el10_0.2
Important: python3.12 security update
{'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'}
10aea3a729e9335d63264b81d44198e9f43297004eb6539c90b790bb91e307e9
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10140.json
CVE-2025-4138
ALSA-2025:10140
python-unversioned-command
Important
3.12.9-2.el10_0.2
< 3.12.9-2.el10_0.2
Important: python3.12 security update
{'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'}
eebecd480d0cca045075873599208ef668d56a377c3462e8a4b3a3abe62c6334
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10140.json
CVE-2025-4435
ALSA-2025:10140
python-unversioned-command
Important
3.12.9-2.el10_0.2
< 3.12.9-2.el10_0.2
Important: python3.12 security update
{'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'}
b9f7466ef7b7b4708e96f447b6cc1663e59ed9e873271f8d375664d8a48ad3ef
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10140.json
CVE-2024-12718
ALSA-2025:10140
python-unversioned-command
Important
3.12.9-2.el10_0.2
< 3.12.9-2.el10_0.2
Important: python3.12 security update
{'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'}
7425b7f092ff6b216749593840313d213652fe5a2ddf3f9f6d3e83882c67d926
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10140.json
CVE-2025-4517
ALSA-2025:10140
python-unversioned-command
Important
3.12.9-2.el10_0.2
< 3.12.9-2.el10_0.2
Important: python3.12 security update
{'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'}
a53c1a53509eb8c5ed5838cbe7482d506d08b577b590b21e5d5a3e0c550ba104
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10371.json
CVE-2025-21991
ALSA-2025:10371
kernel-abi-stablelists
Important
6.12.0-55.20.1.el10_0
< 6.12.0-55.20.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'}
f91ebd5eccced0153c3f026d09f95e102c4273f1d83241f9ea4bb653ed387410
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10371.json
CVE-2025-21759
ALSA-2025:10371
kernel-abi-stablelists
Important
6.12.0-55.20.1.el10_0
< 6.12.0-55.20.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'}
9bde862b8397f9285d08466218af405ba689c5f603d74a7cb10c70a77e61364f
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10371.json
CVE-2025-37799
ALSA-2025:10371
kernel-abi-stablelists
Important
6.12.0-55.20.1.el10_0
< 6.12.0-55.20.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'}
5e996a7d08a27137352e92ed1bc72feb46d5a56daef32a58b03840f244bcaaf2
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9-el-3.0-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
30183cfbd165040160a00314cf78ecab59ef81157d97dec5514bbd34c044ac12
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10371.json
CVE-2025-21991
ALSA-2025:10371
kernel-doc
Important
6.12.0-55.20.1.el10_0
< 6.12.0-55.20.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'}
389ac718b24f8203c35bba914b14babaee828a16146f659fb527b4938637e87e
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10371.json
CVE-2025-21759
ALSA-2025:10371
kernel-doc
Important
6.12.0-55.20.1.el10_0
< 6.12.0-55.20.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'}
392ec41e766901af75fe461cb35a142909726b180fc646be17b8a420148b07f5
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10371.json
CVE-2025-37799
ALSA-2025:10371
kernel-doc
Important
6.12.0-55.20.1.el10_0
< 6.12.0-55.20.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'}
1a44d9700ea2e6fc4589250da41900709c3d7166b8099b3d39c3bedd6d339628
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10549.json
CVE-2025-6032
ALSA-2025:10549
podman-docker
Important
5.4.0-12.el10_0
< 5.4.0-12.el10_0
Important: podman security update
{'_id': {}, 'type': 'security', 'title': 'Important: podman security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'podman-5.4.0-12.el10_0.src.rpm', 'sum': '2368f183f29028195a0412743cedeb7bab161f30c71a9c50498b5a5fcd8d6b5b', 'arch': 'noarch', 'name': 'podman-docker', 'epoch': '6', 'release': '12.el10_0', 'version': '5.4.0', 'filename': 'podman-docker-5.4.0-12.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'podman security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10549', 'href': 'https://access.redhat.com/errata/RHSA-2025:10549', 'type': 'rhsa', 'title': 'RHSA-2025:10549'}, {'id': 'CVE-2025-6032', 'href': 'https://access.redhat.com/security/cve/CVE-2025-6032', 'type': 'cve', 'title': 'CVE-2025-6032'}, {'id': '2372501', 'href': 'https://bugzilla.redhat.com/2372501', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10549', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10549.html', 'type': 'self', 'title': 'ALSA-2025:10549'}], 'description': 'The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. \n\nSecurity Fix(es): \n\n * podman: podman missing TLS verification (CVE-2025-6032)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751932800000}, 'updated_date': {'$date': 1752049033000}, 'updateinfo_id': 'ALSA-2025:10549'}
61d7b8da868949f692c1335d87a9e8c2606175e2df685d7c04190127a4f7b6fa
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9-el-3.0-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
04e2cd2b7ce19d82ea8698cd3c75cc798a69c586ddd86b0f38c061aa9f70237b
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10677.json
CVE-2025-4673
ALSA-2025:10677
golang-tests
Moderate
1.24.4-1.el10_0.alma.1
< 1.24.4-1.el10_0.alma.1
Moderate: golang security update
{'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'}
feed0bdb2d0ea4729e1c4143aba0d418823b22dffa5a4d363719eaf0aa6e9d43
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10677.json
CVE-2025-4673
ALSA-2025:10677
golang-misc
Moderate
1.24.4-1.el10_0.alma.1
< 1.24.4-1.el10_0.alma.1
Moderate: golang security update
{'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'}
277e79a1ffaf3cae938f727bcab3dd3386f2e546d73479a81da437d12a8fae18
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10677.json
CVE-2025-4673
ALSA-2025:10677
golang-docs
Moderate
1.24.4-1.el10_0.alma.1
< 1.24.4-1.el10_0.alma.1
Moderate: golang security update
{'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'}
3f2333038fc14d74e82364be5262da6606bab6dc382df874fb0d7615796a611d
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10677.json
CVE-2025-4673
ALSA-2025:10677
golang-src
Moderate
1.24.4-1.el10_0.alma.1
< 1.24.4-1.el10_0.alma.1
Moderate: golang security update
{'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'}
1488c26211ec357cddfd6b073ddf9ff927c78738e8e2ce504cf2f1452c26ce1c
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10844.json
CVE-2024-6174
ALSA-2025:10844
cloud-init
Important
24.4-3.el10_0.2
< 24.4-3.el10_0.2
Important: cloud-init security update
{'_id': {}, 'type': 'security', 'title': 'Important: cloud-init security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'cloud-init-24.4-3.el10_0.2.src.rpm', 'sum': 'c8703d31e5f37391a9b6dadd4843f0bbc6ef9b36508e47af0b8d9228e66d4893', 'arch': 'noarch', 'name': 'cloud-init', 'epoch': '0', 'release': '3.el10_0.2', 'version': '24.4', 'filename': 'cloud-init-24.4-3.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'cloud-init security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10844', 'href': 'https://access.redhat.com/errata/RHSA-2025:10844', 'type': 'rhsa', 'title': 'RHSA-2025:10844'}, {'id': 'CVE-2024-6174', 'href': 'https://access.redhat.com/security/cve/CVE-2024-6174', 'type': 'cve', 'title': 'CVE-2024-6174'}, {'id': '2374924', 'href': 'https://bugzilla.redhat.com/2374924', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10844', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10844.html', 'type': 'self', 'title': 'ALSA-2025:10844'}], 'description': 'The cloud-init packages provide a set of init scripts for cloud instances. Cloud instances need special scripts to run during initialization to retrieve and install SSH keys, and to let the user run various scripts. \n\nSecurity Fix(es): \n\n * cloud-init: Cloud init permissions flaw (CVE-2024-6174)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752451200000}, 'updated_date': {'$date': 1752821554000}, 'updateinfo_id': 'ALSA-2025:10844'}
14342eb2817edb476f2e51de588ac461ed90e4a92c6994f58763fc82d88dd09b
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10854.json
CVE-2025-22036
ALSA-2025:10854
kernel-doc
Important
6.12.0-55.21.1.el10_0
< 6.12.0-55.21.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'ad3346946a467ace998e0f5d789248c8039c0fe8852edd3c2a57524e5840af93', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'e2609bece1537818a4ca8190eeeefd31484c42563961b01b11357be00d586f3a', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2360231', 'href': 'https://bugzilla.redhat.com/2360231', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-22036', 'href': 'https://access.redhat.com/security/cve/CVE-2025-22036', 'type': 'cve', 'title': 'CVE-2025-22036'}, {'id': 'RHSA-2025:10854', 'href': 'https://access.redhat.com/errata/RHSA-2025:10854', 'type': 'rhsa', 'title': 'RHSA-2025:10854'}, {'id': 'ALSA-2025:10854', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10854.html', 'type': 'self', 'title': 'ALSA-2025:10854'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: exfat: fix random stack corruption after get_block (CVE-2025-22036)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752451200000}, 'updated_date': {'$date': 1753352769000}, 'updateinfo_id': 'ALSA-2025:10854'}
ccf50600107d3e4e0058e176efa06aa899113429f6d4e371e2c42303af051626
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:10854.json
CVE-2025-22036
ALSA-2025:10854
kernel-abi-stablelists
Important
6.12.0-55.21.1.el10_0
< 6.12.0-55.21.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'ad3346946a467ace998e0f5d789248c8039c0fe8852edd3c2a57524e5840af93', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'e2609bece1537818a4ca8190eeeefd31484c42563961b01b11357be00d586f3a', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2360231', 'href': 'https://bugzilla.redhat.com/2360231', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-22036', 'href': 'https://access.redhat.com/security/cve/CVE-2025-22036', 'type': 'cve', 'title': 'CVE-2025-22036'}, {'id': 'RHSA-2025:10854', 'href': 'https://access.redhat.com/errata/RHSA-2025:10854', 'type': 'rhsa', 'title': 'RHSA-2025:10854'}, {'id': 'ALSA-2025:10854', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10854.html', 'type': 'self', 'title': 'ALSA-2025:10854'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: exfat: fix random stack corruption after get_block (CVE-2025-22036)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752451200000}, 'updated_date': {'$date': 1753352769000}, 'updateinfo_id': 'ALSA-2025:10854'}
f3ba3530d7dea45b27abc3f7d698f2d651948cc13ec38c20634fdc84320cb10b
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11066.json
CVE-2025-5702
ALSA-2025:11066
glibc-doc
Moderate
2.39-43.el10_0.alma.1
< 2.39-43.el10_0.alma.1
Moderate: glibc security update
{'_id': {}, 'type': 'security', 'title': 'Moderate: glibc security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'glibc-2.39-43.el10_0.alma.1.src.rpm', 'sum': 'a916ab204aab5d47b09f17cf960266df8947cf09870c33b489356e2a62906c9e', 'arch': 'noarch', 'name': 'glibc-doc', 'epoch': '0', 'release': '43.el10_0.alma.1', 'version': '2.39', 'filename': 'glibc-doc-2.39-43.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'glibc security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11066', 'href': 'https://access.redhat.com/errata/RHSA-2025:11066', 'type': 'rhsa', 'title': 'RHSA-2025:11066'}, {'id': 'CVE-2025-5702', 'href': 'https://access.redhat.com/security/cve/CVE-2025-5702', 'type': 'cve', 'title': 'CVE-2025-5702'}, {'id': '2370472', 'href': 'https://bugzilla.redhat.com/2370472', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11066', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11066.html', 'type': 'self', 'title': 'ALSA-2025:11066'}], 'description': 'The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. \n\nSecurity Fix(es): \n\n * glibc: Vector register overwrite bug in glibc (CVE-2025-5702)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752537600000}, 'updated_date': {'$date': 1752821391000}, 'updateinfo_id': 'ALSA-2025:11066'}
461e9e03945675734ceb0846bc59b10a14afd3ca5d1a90e7c15a51c750cb1b6a
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9-webapps
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
3111d45ebd8641dc5bca5c3755e0d426742355f5b42299e1364005fcd6fa1077
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9-webapps
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
242aaefa21d52ba46dc7b85bf0c3c05ac729d2677962ed8e53775533cbeb6d61
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9-webapps
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
e54c3a7efffea9883ecdb5b1199e0ac9bbb64641c1acf536a94269c90344ade2
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9-el-3.0-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
d5e42184a699fbb65e96532164b00bb47e656fa851b45dd94a04dc9b9416053b
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9-jsp-2.3-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
3b4a78949f58264604a0083f7aee3ea1aff5936da9796b188c283ac08d26e996
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9-jsp-2.3-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
6626bf97c87406b29443374f1b6ac99f3252e8e3241baa280c0cba56e945ab1d
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9-jsp-2.3-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
40818157d585e0932a68797a834e7e875f213855d0c1e6b8cd3f8eca5cd6cc9d
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9-servlet-4.0-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
c57e872ffb337848b30447da5f4b5e4702678123c8effbd68787ae982d3937fb
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9-servlet-4.0-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
7c642643791506c83b02c4570e037167a6b85bf2eaecb3463ea6dda61b3dcfec
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9-servlet-4.0-api
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
cf648a146e0dab8c1f068cf1e4417582c44c0983a912e0115fc15d7a26ccbb2a
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9-admin-webapps
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
d57b7873feca8acb28998ca9ae97d039058557d873cd7b0ae89ff88f574560db
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9-admin-webapps
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
e59f28fabd3f72e5733266002b00f8270bfab9cceeeb559f48d73c169b52bd98
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9-admin-webapps
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
44446c5e871f9e99b0b3031588e500cca3d2820986b980e657a39cb495b3199c
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9-lib
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
7bda594b4bb57d7884f04f8d448f99ee8804a948aa9fbe41079388ed6fc41c39
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9-lib
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
901eb7710077081f2842b3e260203801dbf69eb4d8dc0e0acfdd48c0e066ab05
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9-lib
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
99a978707fee8be7758f4e9f682166757e7198c92247903452733b481a13009c
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9-docs-webapp
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
8f886b73bb792f6d969b0b191347ed8f73917377229c9bd3f9b26f04bff0275a
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9-docs-webapp
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
ae157b9a7873778ec47601282e9be13a8357b95ef5e78c59aa1dc78ba2f61000
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9-docs-webapp
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
c2f94f8aaf8afc2a217702cb7c781342ba2625e2be7db4b07c4d390a1ff51f4a
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-50379
ALSA-2025:11332
tomcat9
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
b94a016b9618c9efc15e213e755a74dd942d7f7fe146c008cc8fd4d23a1b60c7
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2024-56337
ALSA-2025:11332
tomcat9
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
4d90f3093c62a6e4ee6330c86042a1187252b52074c563fe08f6c482ff47a40e
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11332.json
CVE-2025-31650
ALSA-2025:11332
tomcat9
Important
9.0.87-5.el10_0.1
< 9.0.87-5.el10_0.1
Important: tomcat9 security update
{'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'}
b52b5b96d69e8be02b77da4c4a6a26e599af8391a4c5208cc6688d1ac9ae2e9d
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2024-57980
ALSA-2025:11428
kernel-abi-stablelists
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
1ca1d79c6b3b5f99d93de04824c695e23135bbd17fe874d90f1edb5ea57887c6
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2025-37958
ALSA-2025:11428
kernel-abi-stablelists
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
9888a06e71a13252efd98dd543ea19fcf6211b443f69eb5d11b41adfde3d73c6
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2025-38089
ALSA-2025:11428
kernel-abi-stablelists
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
4e5c4a0c091ca20fc9a486faf55bb0af2d12bdb94b95ea4204dc49e46188f4b8
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2025-21905
ALSA-2025:11428
kernel-abi-stablelists
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
32a66aaeb7cbeca6197d26896ff73c0cd5a3b8f142d1720a6c216fa82dc1fb50
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2024-58002
ALSA-2025:11428
kernel-abi-stablelists
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
e024b946de3a51ddb400a521d415e92e7eaf7589f9401e53f9d8c1f06537ce5a
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2024-57980
ALSA-2025:11428
kernel-doc
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
d648585d3f30977b881370476d0ca70dc3cfc7b91f63be56fdd4170a178ec879
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2025-37958
ALSA-2025:11428
kernel-doc
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
e2915a6b3ab1aaa05bdca0219504bba02283635fb088fa21127d2b413bc22074
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2025-38089
ALSA-2025:11428
kernel-doc
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
5f656e5a2e78df1656572a804645d8b66c68840c3ff169eafb4aaf0b895b0145
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2025-21905
ALSA-2025:11428
kernel-doc
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
ae87ea5d5391806efed3d7fb412ffe915a576ad1f5a6e4f1f02c276125649e11
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11428.json
CVE-2024-58002
ALSA-2025:11428
kernel-doc
Important
6.12.0-55.22.1.el10_0
< 6.12.0-55.22.1.el10_0
Important: kernel security update
{'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'}
c9fca3f28fd3a86c7a573b173dd79e5059d243b3e53331ee9547ea085ccf98c6
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27613
ALSA-2025:11533
git-gui
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
653b10145b0411f0692b1ae59200622b3ba5e82190e0d295b8e193619351f485
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48384
ALSA-2025:11533
git-gui
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
514781a0375e6d3cb9795c5d44b61134b93ff616b572de25a2a9741e7b30caa1
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48385
ALSA-2025:11533
git-gui
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
ecca41f04f8be0b9d78b96c27dd0ef2c5086c04dfd19a8d0d6bfe4e3afea4fef
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-50349
ALSA-2025:11533
git-gui
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
dcd38100dc0839bff34e32c169a9044135303707af5cb85f31057ef9bbe01099
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27614
ALSA-2025:11533
git-gui
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
ae05f86feb22fb54a2890f6c73381fc0494556f28b8133e9513ffd20ad6868ef
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-46835
ALSA-2025:11533
git-gui
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
3532539ede11e8f8f13a691dba8781de6f33fa8456bdd80e7aac5512d1e7b02b
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-52006
ALSA-2025:11533
git-gui
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
f4f4fb8a356cf91c09a9916baaa81259bacc97e2cb853c2e48690009caf36e4c
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27613
ALSA-2025:11533
perl-Git-SVN
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
857fc1ce53ea345bdcea1c9ae7558389de89e6807c7ef357fcc8ac8103ece783
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48384
ALSA-2025:11533
perl-Git-SVN
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
50b9ee83fb125602246d1662ae2a81b5a9327c8d0ff88004705833f5c5099ac4
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48385
ALSA-2025:11533
perl-Git-SVN
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
4c7142dddaec6082c2504848a6b9c23bf6e16c3c74bca32ad73fef16b13528c1
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-50349
ALSA-2025:11533
perl-Git-SVN
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
b415da8d0b6e45e0e3b8646594063011b07ea4fc49abb3380e66cee3d98c8b81
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27614
ALSA-2025:11533
perl-Git-SVN
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
188b94e7574a03d402165fcc87e900f94e5faded53ed0e4c0def192499ca36ac
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-46835
ALSA-2025:11533
perl-Git-SVN
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
7dcd465a5c043bfac2f3fcdc8be53f8785ef954a695717de94ffd57f2fae999d
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-52006
ALSA-2025:11533
perl-Git-SVN
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
2583eccc79db8ae72c89b3809a780f16a6fc3b576dd06b46d7459b871e585ffa
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27613
ALSA-2025:11533
gitweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
b512cdf0629a71c17e641c9476ebfe3ebafba5ad0b0ef9e76fdcb280b20689be
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48384
ALSA-2025:11533
gitweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
ac6325032d01fe3a34ae499c7f1548c49323bd24787736a89436eb441399de89
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48385
ALSA-2025:11533
gitweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
3a157473e40107529be0fa8d2a3ad94dc5b02bdfcda83777268511b41ed2f17d
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-50349
ALSA-2025:11533
gitweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
43a5917ca082b47371f77fc361c7a87b693e7667357a9d8e28877f67906f3464
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27614
ALSA-2025:11533
gitweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
b32bef26ddfe4616b331166ca571c4d6ec31fca38bec3c15a0b4d9f0d0e71ea4
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-46835
ALSA-2025:11533
gitweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
485682ff1794f3f2bee78f385551b6ccdb0f4ebb978cdd73babfbe91e7860bbe
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-52006
ALSA-2025:11533
gitweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
d2a06e712702357a3ac46083d10184331e94c404bbdaec4e2a585f306038e8df
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27613
ALSA-2025:11533
gitk
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
ea76ea8bc07da45aa953d1afd2d9d116e5406b9cdc8266703d5050187424b8b0
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48384
ALSA-2025:11533
gitk
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
62a844f58d1f9046c53b3181f8f9a942fb7e74bc9c5f937fd06a371e2486f8fb
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48385
ALSA-2025:11533
gitk
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
855f92de29eb0c229bbaf5283db70c2362397535e9d14dcf96931ec81a190d84
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-50349
ALSA-2025:11533
gitk
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
cdfbdba4d749cdd213ea1c83b16078c8be7f52a600e72bf08b02a1ae3b6436b4
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27614
ALSA-2025:11533
gitk
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
3c065a77bc437420cb796f1d8122067269b22cd759cba52725cc3fc430f3f729
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-46835
ALSA-2025:11533
gitk
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
b80d3b80abef71800d8ce1e2a07a6d3aa6d88cc3d308c6e1b360e9fa625714be
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-52006
ALSA-2025:11533
gitk
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
b77b610b5574afefc32eab75bd1fbdf18d9f4bf412e5c956bebf48f48de3bbcc
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27613
ALSA-2025:11533
git-core-doc
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
5b81655df9047c2fda482c8df64e4571b24683cf59212b0472c2dfa9e31c38c6
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48384
ALSA-2025:11533
git-core-doc
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
690d6d92c5678f74199f01cd0905a7a2907368fbe079dc8f2eb36bc8abda9eed
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48385
ALSA-2025:11533
git-core-doc
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
7c9f1e81a9c9ece0233d6c1502efdd767fef946b3e04a836280bc955172cf465
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-50349
ALSA-2025:11533
git-core-doc
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
ba2cb33291a187e3d93e1195124b784de2e605b57f800d5aab835628222fdc2c
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27614
ALSA-2025:11533
git-core-doc
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
a79dd5426e4cbb86750b6637a3b404cf3248ff633f44d03c088be61f105122d3
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-46835
ALSA-2025:11533
git-core-doc
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
cb2c27867786df44ff67d76a6f5f759cdcbb5a8bbb31c78c2f2c7f6241b59cb0
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-52006
ALSA-2025:11533
git-core-doc
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
c4babfe52f7f8525957f91d95080d54218ede8803f1bf92fe669bec690d6867e
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27613
ALSA-2025:11533
git-email
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
5e2c9c7dc4c7458509d7a824bc419826b80d37f4712234e27bf19af345067160
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48384
ALSA-2025:11533
git-email
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
48965213fcf6e13373eba74275752b1adc64d3bcff88651ea8b3a601cfc70dbe
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48385
ALSA-2025:11533
git-email
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
1315a62251b04a3608127ce714e905f430df2ea4a39eead136c8258ca8a78983
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-50349
ALSA-2025:11533
git-email
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
33a2d665e2ac8b34f91a1063dc2e045e83c6a01a117b113a86d5c982ca65a216
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27614
ALSA-2025:11533
git-email
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
8e835d326daffcea37fbac283b94ea2ecf88d572316fca7739707f5b9817c627
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-46835
ALSA-2025:11533
git-email
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
aff548036a5c837953b57fa33cfa46c2de9d0114dd51d09a5471910d2fb5fce5
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-52006
ALSA-2025:11533
git-email
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
5edc4f3afac6514d0744636551be35c4844920e1e41a0fab47a148715eb19c51
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-27613
ALSA-2025:11533
git-instaweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
5ac2b2ba0acbd74ca9b628ba53402d27793fc4154d836c428fb1ac7785fda684
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48384
ALSA-2025:11533
git-instaweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
cb08d2db0f2c2f6a4d24b9163dbf2e5ca2e26c0b81ad216046885b15cfcb2ed6
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2025-48385
ALSA-2025:11533
git-instaweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
78e9dc7ca3ddfcc6517875565eeb81b5255487f8d5739be87f888c11ccfd0d6e
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00
alma
alma/10/2025/ALSA-2025:11533.json
CVE-2024-50349
ALSA-2025:11533
git-instaweb
Important
2.47.3-1.el10_0
< 2.47.3-1.el10_0
Important: git security update
{'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'}
b8480ee261b1fe2a6b8f54fc5839e35011e0ec430fa1b2f2e3484c4a2def9f48
2026-05-30 00:55:19.885834+03:00
2026-05-30 00:55:19.885834+03:00