Zeros312
alma | alma/10/2025/ALSA-2025:10140.json | CVE-2025-4330 | ALSA-2025:10140 | python-unversioned-command | Important | 3.12.9-2.el10_0.2 | < 3.12.9-2.el10_0.2 | Important: python3.12 security update | {'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'} | 10aea3a729e9335d63264b81d44198e9f43297004eb6539c90b790bb91e307e9 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10140.json | CVE-2025-4138 | ALSA-2025:10140 | python-unversioned-command | Important | 3.12.9-2.el10_0.2 | < 3.12.9-2.el10_0.2 | Important: python3.12 security update | {'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'} | eebecd480d0cca045075873599208ef668d56a377c3462e8a4b3a3abe62c6334 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10140.json | CVE-2025-4435 | ALSA-2025:10140 | python-unversioned-command | Important | 3.12.9-2.el10_0.2 | < 3.12.9-2.el10_0.2 | Important: python3.12 security update | {'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'} | b9f7466ef7b7b4708e96f447b6cc1663e59ed9e873271f8d375664d8a48ad3ef | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10140.json | CVE-2024-12718 | ALSA-2025:10140 | python-unversioned-command | Important | 3.12.9-2.el10_0.2 | < 3.12.9-2.el10_0.2 | Important: python3.12 security update | {'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'} | 7425b7f092ff6b216749593840313d213652fe5a2ddf3f9f6d3e83882c67d926 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10140.json | CVE-2025-4517 | ALSA-2025:10140 | python-unversioned-command | Important | 3.12.9-2.el10_0.2 | < 3.12.9-2.el10_0.2 | Important: python3.12 security update | {'_id': {}, 'type': 'security', 'title': 'Important: python3.12 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'python3.12-3.12.9-2.el10_0.2.src.rpm', 'sum': 'd255de67dd2efc228d23f32fbcb80a822a9bed2e8f9bf1c7699c8598ac684ba3', 'arch': 'noarch', 'name': 'python-unversioned-command', 'epoch': '0', 'release': '2.el10_0.2', 'version': '3.12.9', 'filename': 'python-unversioned-command-3.12.9-2.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'python3.12 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10140', 'href': 'https://access.redhat.com/errata/RHSA-2025:10140', 'type': 'rhsa', 'title': 'RHSA-2025:10140'}, {'id': 'CVE-2024-12718', 'href': 'https://access.redhat.com/security/cve/CVE-2024-12718', 'type': 'cve', 'title': 'CVE-2024-12718'}, {'id': 'CVE-2025-4138', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4138', 'type': 'cve', 'title': 'CVE-2025-4138'}, {'id': 'CVE-2025-4330', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4330', 'type': 'cve', 'title': 'CVE-2025-4330'}, {'id': 'CVE-2025-4435', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4435', 'type': 'cve', 'title': 'CVE-2025-4435'}, {'id': 'CVE-2025-4517', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4517', 'type': 'cve', 'title': 'CVE-2025-4517'}, {'id': '2370010', 'href': 'https://bugzilla.redhat.com/2370010', 'type': 'bugzilla', 'title': ''}, {'id': '2370013', 'href': 'https://bugzilla.redhat.com/2370013', 'type': 'bugzilla', 'title': ''}, {'id': '2370014', 'href': 'https://bugzilla.redhat.com/2370014', 'type': 'bugzilla', 'title': ''}, {'id': '2370016', 'href': 'https://bugzilla.redhat.com/2370016', 'type': 'bugzilla', 'title': ''}, {'id': '2372426', 'href': 'https://bugzilla.redhat.com/2372426', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10140', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10140.html', 'type': 'self', 'title': 'ALSA-2025:10140'}], 'description': 'Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es): \n\n * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)\n * cpython: Bypass extraction filter to modify file metadata outside extraction directory (CVE-2024-12718)\n * cpython: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)\n * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)\n * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751328000000}, 'updated_date': {'$date': 1751529230000}, 'updateinfo_id': 'ALSA-2025:10140'} | a53c1a53509eb8c5ed5838cbe7482d506d08b577b590b21e5d5a3e0c550ba104 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10371.json | CVE-2025-21991 | ALSA-2025:10371 | kernel-abi-stablelists | Important | 6.12.0-55.20.1.el10_0 | < 6.12.0-55.20.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'} | f91ebd5eccced0153c3f026d09f95e102c4273f1d83241f9ea4bb653ed387410 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10371.json | CVE-2025-21759 | ALSA-2025:10371 | kernel-abi-stablelists | Important | 6.12.0-55.20.1.el10_0 | < 6.12.0-55.20.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'} | 9bde862b8397f9285d08466218af405ba689c5f603d74a7cb10c70a77e61364f | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10371.json | CVE-2025-37799 | ALSA-2025:10371 | kernel-abi-stablelists | Important | 6.12.0-55.20.1.el10_0 | < 6.12.0-55.20.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'} | 5e996a7d08a27137352e92ed1bc72feb46d5a56daef32a58b03840f244bcaaf2 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9-el-3.0-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 30183cfbd165040160a00314cf78ecab59ef81157d97dec5514bbd34c044ac12 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10371.json | CVE-2025-21991 | ALSA-2025:10371 | kernel-doc | Important | 6.12.0-55.20.1.el10_0 | < 6.12.0-55.20.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'} | 389ac718b24f8203c35bba914b14babaee828a16146f659fb527b4938637e87e | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10371.json | CVE-2025-21759 | ALSA-2025:10371 | kernel-doc | Important | 6.12.0-55.20.1.el10_0 | < 6.12.0-55.20.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'} | 392ec41e766901af75fe461cb35a142909726b180fc646be17b8a420148b07f5 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10371.json | CVE-2025-37799 | ALSA-2025:10371 | kernel-doc | Important | 6.12.0-55.20.1.el10_0 | < 6.12.0-55.20.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': '8edbbaaaf2ea0df93b9105667c47d1a2f4a49012b084a942bfe057ae5276824b', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.20.1.el10_0.src.rpm', 'sum': 'a6bf58e27d9a6854cbfc816edd581f2604ac2a153452f1a114c2b0faaec2fbc1', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.20.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.20.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348596', 'href': 'https://bugzilla.redhat.com/2348596', 'type': 'bugzilla', 'title': ''}, {'id': '2356917', 'href': 'https://bugzilla.redhat.com/2356917', 'type': 'bugzilla', 'title': ''}, {'id': '2363876', 'href': 'https://bugzilla.redhat.com/2363876', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-21759', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21759', 'type': 'cve', 'title': 'CVE-2025-21759'}, {'id': 'CVE-2025-21991', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21991', 'type': 'cve', 'title': 'CVE-2025-21991'}, {'id': 'CVE-2025-37799', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37799', 'type': 'cve', 'title': 'CVE-2025-37799'}, {'id': 'RHSA-2025:10371', 'href': 'https://access.redhat.com/errata/RHSA-2025:10371', 'type': 'rhsa', 'title': 'RHSA-2025:10371'}, {'id': 'ALSA-2025:10371', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10371.html', 'type': 'self', 'title': 'ALSA-2025:10371'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)\n * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)\n * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751846400000}, 'updated_date': {'$date': 1752154767000}, 'updateinfo_id': 'ALSA-2025:10371'} | 1a44d9700ea2e6fc4589250da41900709c3d7166b8099b3d39c3bedd6d339628 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10549.json | CVE-2025-6032 | ALSA-2025:10549 | podman-docker | Important | 5.4.0-12.el10_0 | < 5.4.0-12.el10_0 | Important: podman security update | {'_id': {}, 'type': 'security', 'title': 'Important: podman security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'podman-5.4.0-12.el10_0.src.rpm', 'sum': '2368f183f29028195a0412743cedeb7bab161f30c71a9c50498b5a5fcd8d6b5b', 'arch': 'noarch', 'name': 'podman-docker', 'epoch': '6', 'release': '12.el10_0', 'version': '5.4.0', 'filename': 'podman-docker-5.4.0-12.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'podman security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10549', 'href': 'https://access.redhat.com/errata/RHSA-2025:10549', 'type': 'rhsa', 'title': 'RHSA-2025:10549'}, {'id': 'CVE-2025-6032', 'href': 'https://access.redhat.com/security/cve/CVE-2025-6032', 'type': 'cve', 'title': 'CVE-2025-6032'}, {'id': '2372501', 'href': 'https://bugzilla.redhat.com/2372501', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10549', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10549.html', 'type': 'self', 'title': 'ALSA-2025:10549'}], 'description': 'The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. \n\nSecurity Fix(es): \n\n * podman: podman missing TLS verification (CVE-2025-6032)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1751932800000}, 'updated_date': {'$date': 1752049033000}, 'updateinfo_id': 'ALSA-2025:10549'} | 61d7b8da868949f692c1335d87a9e8c2606175e2df685d7c04190127a4f7b6fa | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9-el-3.0-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 04e2cd2b7ce19d82ea8698cd3c75cc798a69c586ddd86b0f38c061aa9f70237b | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10677.json | CVE-2025-4673 | ALSA-2025:10677 | golang-tests | Moderate | 1.24.4-1.el10_0.alma.1 | < 1.24.4-1.el10_0.alma.1 | Moderate: golang security update | {'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'} | feed0bdb2d0ea4729e1c4143aba0d418823b22dffa5a4d363719eaf0aa6e9d43 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10677.json | CVE-2025-4673 | ALSA-2025:10677 | golang-misc | Moderate | 1.24.4-1.el10_0.alma.1 | < 1.24.4-1.el10_0.alma.1 | Moderate: golang security update | {'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'} | 277e79a1ffaf3cae938f727bcab3dd3386f2e546d73479a81da437d12a8fae18 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10677.json | CVE-2025-4673 | ALSA-2025:10677 | golang-docs | Moderate | 1.24.4-1.el10_0.alma.1 | < 1.24.4-1.el10_0.alma.1 | Moderate: golang security update | {'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'} | 3f2333038fc14d74e82364be5262da6606bab6dc382df874fb0d7615796a611d | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10677.json | CVE-2025-4673 | ALSA-2025:10677 | golang-src | Moderate | 1.24.4-1.el10_0.alma.1 | < 1.24.4-1.el10_0.alma.1 | Moderate: golang security update | {'_id': {}, 'type': 'security', 'title': 'Moderate: golang security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': '215b44a89bf213d6d3fd17512e4038c977aadf945f56e791b5c4e46a5650b18d', 'arch': 'noarch', 'name': 'golang-tests', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-tests-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'b87d1b172bcedf411706d911a8d1e06d9ca34d506e208428cc593dce9adf2478', 'arch': 'noarch', 'name': 'golang-misc', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-misc-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ce2dda23055ea1ec2ae6c285c0ac9d3a78dd347f1bcd3dbc29e55ef11db99f66', 'arch': 'noarch', 'name': 'golang-docs', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-docs-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'golang-1.24.4-1.el10_0.alma.1.src.rpm', 'sum': 'ea025f4b76182a4fbc8f4fc988745046cec66e412c57867ace45bf701dcd7229', 'arch': 'noarch', 'name': 'golang-src', 'epoch': '0', 'release': '1.el10_0.alma.1', 'version': '1.24.4', 'filename': 'golang-src-1.24.4-1.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'golang security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10677', 'href': 'https://access.redhat.com/errata/RHSA-2025:10677', 'type': 'rhsa', 'title': 'RHSA-2025:10677'}, {'id': 'CVE-2025-4673', 'href': 'https://access.redhat.com/security/cve/CVE-2025-4673', 'type': 'cve', 'title': 'CVE-2025-4673'}, {'id': '2373305', 'href': 'https://bugzilla.redhat.com/2373305', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10677', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10677.html', 'type': 'self', 'title': 'ALSA-2025:10677'}], 'description': 'The golang packages provide the Go programming language compiler. \n\nSecurity Fix(es): \n\n * net/[http:](http:) Sensitive headers not cleared on cross-origin redirect in net/http (CVE-2025-4673)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752019200000}, 'updated_date': {'$date': 1752184592000}, 'updateinfo_id': 'ALSA-2025:10677'} | 1488c26211ec357cddfd6b073ddf9ff927c78738e8e2ce504cf2f1452c26ce1c | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10844.json | CVE-2024-6174 | ALSA-2025:10844 | cloud-init | Important | 24.4-3.el10_0.2 | < 24.4-3.el10_0.2 | Important: cloud-init security update | {'_id': {}, 'type': 'security', 'title': 'Important: cloud-init security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'cloud-init-24.4-3.el10_0.2.src.rpm', 'sum': 'c8703d31e5f37391a9b6dadd4843f0bbc6ef9b36508e47af0b8d9228e66d4893', 'arch': 'noarch', 'name': 'cloud-init', 'epoch': '0', 'release': '3.el10_0.2', 'version': '24.4', 'filename': 'cloud-init-24.4-3.el10_0.2.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'cloud-init security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:10844', 'href': 'https://access.redhat.com/errata/RHSA-2025:10844', 'type': 'rhsa', 'title': 'RHSA-2025:10844'}, {'id': 'CVE-2024-6174', 'href': 'https://access.redhat.com/security/cve/CVE-2024-6174', 'type': 'cve', 'title': 'CVE-2024-6174'}, {'id': '2374924', 'href': 'https://bugzilla.redhat.com/2374924', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:10844', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10844.html', 'type': 'self', 'title': 'ALSA-2025:10844'}], 'description': 'The cloud-init packages provide a set of init scripts for cloud instances. Cloud instances need special scripts to run during initialization to retrieve and install SSH keys, and to let the user run various scripts. \n\nSecurity Fix(es): \n\n * cloud-init: Cloud init permissions flaw (CVE-2024-6174)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752451200000}, 'updated_date': {'$date': 1752821554000}, 'updateinfo_id': 'ALSA-2025:10844'} | 14342eb2817edb476f2e51de588ac461ed90e4a92c6994f58763fc82d88dd09b | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10854.json | CVE-2025-22036 | ALSA-2025:10854 | kernel-doc | Important | 6.12.0-55.21.1.el10_0 | < 6.12.0-55.21.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'ad3346946a467ace998e0f5d789248c8039c0fe8852edd3c2a57524e5840af93', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'e2609bece1537818a4ca8190eeeefd31484c42563961b01b11357be00d586f3a', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2360231', 'href': 'https://bugzilla.redhat.com/2360231', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-22036', 'href': 'https://access.redhat.com/security/cve/CVE-2025-22036', 'type': 'cve', 'title': 'CVE-2025-22036'}, {'id': 'RHSA-2025:10854', 'href': 'https://access.redhat.com/errata/RHSA-2025:10854', 'type': 'rhsa', 'title': 'RHSA-2025:10854'}, {'id': 'ALSA-2025:10854', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10854.html', 'type': 'self', 'title': 'ALSA-2025:10854'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: exfat: fix random stack corruption after get_block (CVE-2025-22036)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752451200000}, 'updated_date': {'$date': 1753352769000}, 'updateinfo_id': 'ALSA-2025:10854'} | ccf50600107d3e4e0058e176efa06aa899113429f6d4e371e2c42303af051626 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:10854.json | CVE-2025-22036 | ALSA-2025:10854 | kernel-abi-stablelists | Important | 6.12.0-55.21.1.el10_0 | < 6.12.0-55.21.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'ad3346946a467ace998e0f5d789248c8039c0fe8852edd3c2a57524e5840af93', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.21.1.el10_0.src.rpm', 'sum': 'e2609bece1537818a4ca8190eeeefd31484c42563961b01b11357be00d586f3a', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.21.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.21.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2360231', 'href': 'https://bugzilla.redhat.com/2360231', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2025-22036', 'href': 'https://access.redhat.com/security/cve/CVE-2025-22036', 'type': 'cve', 'title': 'CVE-2025-22036'}, {'id': 'RHSA-2025:10854', 'href': 'https://access.redhat.com/errata/RHSA-2025:10854', 'type': 'rhsa', 'title': 'RHSA-2025:10854'}, {'id': 'ALSA-2025:10854', 'href': 'https://errata.almalinux.org/10/ALSA-2025-10854.html', 'type': 'self', 'title': 'ALSA-2025:10854'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: exfat: fix random stack corruption after get_block (CVE-2025-22036)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752451200000}, 'updated_date': {'$date': 1753352769000}, 'updateinfo_id': 'ALSA-2025:10854'} | f3ba3530d7dea45b27abc3f7d698f2d651948cc13ec38c20634fdc84320cb10b | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11066.json | CVE-2025-5702 | ALSA-2025:11066 | glibc-doc | Moderate | 2.39-43.el10_0.alma.1 | < 2.39-43.el10_0.alma.1 | Moderate: glibc security update | {'_id': {}, 'type': 'security', 'title': 'Moderate: glibc security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'glibc-2.39-43.el10_0.alma.1.src.rpm', 'sum': 'a916ab204aab5d47b09f17cf960266df8947cf09870c33b489356e2a62906c9e', 'arch': 'noarch', 'name': 'glibc-doc', 'epoch': '0', 'release': '43.el10_0.alma.1', 'version': '2.39', 'filename': 'glibc-doc-2.39-43.el10_0.alma.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'glibc security update', 'version': '3', 'severity': 'Moderate', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11066', 'href': 'https://access.redhat.com/errata/RHSA-2025:11066', 'type': 'rhsa', 'title': 'RHSA-2025:11066'}, {'id': 'CVE-2025-5702', 'href': 'https://access.redhat.com/security/cve/CVE-2025-5702', 'type': 'cve', 'title': 'CVE-2025-5702'}, {'id': '2370472', 'href': 'https://bugzilla.redhat.com/2370472', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11066', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11066.html', 'type': 'self', 'title': 'ALSA-2025:11066'}], 'description': 'The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. \n\nSecurity Fix(es): \n\n * glibc: Vector register overwrite bug in glibc (CVE-2025-5702)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752537600000}, 'updated_date': {'$date': 1752821391000}, 'updateinfo_id': 'ALSA-2025:11066'} | 461e9e03945675734ceb0846bc59b10a14afd3ca5d1a90e7c15a51c750cb1b6a | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9-webapps | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 3111d45ebd8641dc5bca5c3755e0d426742355f5b42299e1364005fcd6fa1077 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9-webapps | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 242aaefa21d52ba46dc7b85bf0c3c05ac729d2677962ed8e53775533cbeb6d61 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9-webapps | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | e54c3a7efffea9883ecdb5b1199e0ac9bbb64641c1acf536a94269c90344ade2 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9-el-3.0-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | d5e42184a699fbb65e96532164b00bb47e656fa851b45dd94a04dc9b9416053b | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9-jsp-2.3-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 3b4a78949f58264604a0083f7aee3ea1aff5936da9796b188c283ac08d26e996 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9-jsp-2.3-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 6626bf97c87406b29443374f1b6ac99f3252e8e3241baa280c0cba56e945ab1d | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9-jsp-2.3-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 40818157d585e0932a68797a834e7e875f213855d0c1e6b8cd3f8eca5cd6cc9d | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9-servlet-4.0-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | c57e872ffb337848b30447da5f4b5e4702678123c8effbd68787ae982d3937fb | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9-servlet-4.0-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 7c642643791506c83b02c4570e037167a6b85bf2eaecb3463ea6dda61b3dcfec | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9-servlet-4.0-api | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | cf648a146e0dab8c1f068cf1e4417582c44c0983a912e0115fc15d7a26ccbb2a | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9-admin-webapps | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | d57b7873feca8acb28998ca9ae97d039058557d873cd7b0ae89ff88f574560db | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9-admin-webapps | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | e59f28fabd3f72e5733266002b00f8270bfab9cceeeb559f48d73c169b52bd98 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9-admin-webapps | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 44446c5e871f9e99b0b3031588e500cca3d2820986b980e657a39cb495b3199c | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9-lib | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 7bda594b4bb57d7884f04f8d448f99ee8804a948aa9fbe41079388ed6fc41c39 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9-lib | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 901eb7710077081f2842b3e260203801dbf69eb4d8dc0e0acfdd48c0e066ab05 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9-lib | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 99a978707fee8be7758f4e9f682166757e7198c92247903452733b481a13009c | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9-docs-webapp | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 8f886b73bb792f6d969b0b191347ed8f73917377229c9bd3f9b26f04bff0275a | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9-docs-webapp | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | ae157b9a7873778ec47601282e9be13a8357b95ef5e78c59aa1dc78ba2f61000 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9-docs-webapp | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | c2f94f8aaf8afc2a217702cb7c781342ba2625e2be7db4b07c4d390a1ff51f4a | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-50379 | ALSA-2025:11332 | tomcat9 | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | b94a016b9618c9efc15e213e755a74dd942d7f7fe146c008cc8fd4d23a1b60c7 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2024-56337 | ALSA-2025:11332 | tomcat9 | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | 4d90f3093c62a6e4ee6330c86042a1187252b52074c563fe08f6c482ff47a40e | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11332.json | CVE-2025-31650 | ALSA-2025:11332 | tomcat9 | Important | 9.0.87-5.el10_0.1 | < 9.0.87-5.el10_0.1 | Important: tomcat9 security update | {'_id': {}, 'type': 'security', 'title': 'Important: tomcat9 security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa', 'arch': 'noarch', 'name': 'tomcat9-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0', 'arch': 'noarch', 'name': 'tomcat9-el-3.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c', 'arch': 'noarch', 'name': 'tomcat9-jsp-2.3-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee', 'arch': 'noarch', 'name': 'tomcat9-servlet-4.0-api', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': '6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe', 'arch': 'noarch', 'name': 'tomcat9-admin-webapps', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1', 'arch': 'noarch', 'name': 'tomcat9-lib', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092', 'arch': 'noarch', 'name': 'tomcat9-docs-webapp', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'tomcat9-9.0.87-5.el10_0.1.src.rpm', 'sum': 'e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4', 'arch': 'noarch', 'name': 'tomcat9', 'epoch': '1', 'release': '5.el10_0.1', 'version': '9.0.87', 'filename': 'tomcat9-9.0.87-5.el10_0.1.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'tomcat9 security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11332', 'href': 'https://access.redhat.com/errata/RHSA-2025:11332', 'type': 'rhsa', 'title': 'RHSA-2025:11332'}, {'id': 'CVE-2024-56337', 'href': 'https://access.redhat.com/security/cve/CVE-2024-56337', 'type': 'cve', 'title': 'CVE-2024-56337'}, {'id': 'CVE-2025-31650', 'href': 'https://access.redhat.com/security/cve/CVE-2025-31650', 'type': 'cve', 'title': 'CVE-2025-31650'}, {'id': '2333521', 'href': 'https://bugzilla.redhat.com/2333521', 'type': 'bugzilla', 'title': ''}, {'id': '2362783', 'href': 'https://bugzilla.redhat.com/2362783', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11332', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11332.html', 'type': 'self', 'title': 'ALSA-2025:11332'}], 'description': 'Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. \n\nSecurity Fix(es): \n\n * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)\n * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1752624000000}, 'updated_date': {'$date': 1753092219000}, 'updateinfo_id': 'ALSA-2025:11332'} | b52b5b96d69e8be02b77da4c4a6a26e599af8391a4c5208cc6688d1ac9ae2e9d | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2024-57980 | ALSA-2025:11428 | kernel-abi-stablelists | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | 1ca1d79c6b3b5f99d93de04824c695e23135bbd17fe874d90f1edb5ea57887c6 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2025-37958 | ALSA-2025:11428 | kernel-abi-stablelists | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | 9888a06e71a13252efd98dd543ea19fcf6211b443f69eb5d11b41adfde3d73c6 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2025-38089 | ALSA-2025:11428 | kernel-abi-stablelists | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | 4e5c4a0c091ca20fc9a486faf55bb0af2d12bdb94b95ea4204dc49e46188f4b8 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2025-21905 | ALSA-2025:11428 | kernel-abi-stablelists | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | 32a66aaeb7cbeca6197d26896ff73c0cd5a3b8f142d1720a6c216fa82dc1fb50 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2024-58002 | ALSA-2025:11428 | kernel-abi-stablelists | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | e024b946de3a51ddb400a521d415e92e7eaf7589f9401e53f9d8c1f06537ce5a | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2024-57980 | ALSA-2025:11428 | kernel-doc | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | d648585d3f30977b881370476d0ca70dc3cfc7b91f63be56fdd4170a178ec879 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2025-37958 | ALSA-2025:11428 | kernel-doc | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | e2915a6b3ab1aaa05bdca0219504bba02283635fb088fa21127d2b413bc22074 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2025-38089 | ALSA-2025:11428 | kernel-doc | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | 5f656e5a2e78df1656572a804645d8b66c68840c3ff169eafb4aaf0b895b0145 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2025-21905 | ALSA-2025:11428 | kernel-doc | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | ae87ea5d5391806efed3d7fb412ffe915a576ad1f5a6e4f1f02c276125649e11 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11428.json | CVE-2024-58002 | ALSA-2025:11428 | kernel-doc | Important | 6.12.0-55.22.1.el10_0 | < 6.12.0-55.22.1.el10_0 | Important: kernel security update | {'_id': {}, 'type': 'security', 'title': 'Important: kernel security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'ae0dff43f61898aca8de8616d6e745448615a1ac0d13a70cf084c65350091c99', 'arch': 'noarch', 'name': 'kernel-abi-stablelists', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-abi-stablelists-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'kernel-6.12.0-55.22.1.el10_0.src.rpm', 'sum': 'cb61b844a7ed659450b42cf8b5a9b959f2e2616922e9a562d210db16bb975adf', 'arch': 'noarch', 'name': 'kernel-doc', 'epoch': '0', 'release': '55.22.1.el10_0', 'version': '6.12.0', 'filename': 'kernel-doc-6.12.0-55.22.1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-baseos-rpms__10_0_default'}, 'release': '0', 'summary': 'kernel security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': '2348513', 'href': 'https://bugzilla.redhat.com/2348513', 'type': 'bugzilla', 'title': ''}, {'id': '2348599', 'href': 'https://bugzilla.redhat.com/2348599', 'type': 'bugzilla', 'title': ''}, {'id': '2356613', 'href': 'https://bugzilla.redhat.com/2356613', 'type': 'bugzilla', 'title': ''}, {'id': '2367572', 'href': 'https://bugzilla.redhat.com/2367572', 'type': 'bugzilla', 'title': ''}, {'id': '2375529', 'href': 'https://bugzilla.redhat.com/2375529', 'type': 'bugzilla', 'title': ''}, {'id': 'CVE-2024-57980', 'href': 'https://access.redhat.com/security/cve/CVE-2024-57980', 'type': 'cve', 'title': 'CVE-2024-57980'}, {'id': 'CVE-2024-58002', 'href': 'https://access.redhat.com/security/cve/CVE-2024-58002', 'type': 'cve', 'title': 'CVE-2024-58002'}, {'id': 'CVE-2025-21905', 'href': 'https://access.redhat.com/security/cve/CVE-2025-21905', 'type': 'cve', 'title': 'CVE-2025-21905'}, {'id': 'CVE-2025-37958', 'href': 'https://access.redhat.com/security/cve/CVE-2025-37958', 'type': 'cve', 'title': 'CVE-2025-37958'}, {'id': 'CVE-2025-38089', 'href': 'https://access.redhat.com/security/cve/CVE-2025-38089', 'type': 'cve', 'title': 'CVE-2025-38089'}, {'id': 'RHSA-2025:11428', 'href': 'https://access.redhat.com/errata/RHSA-2025:11428', 'type': 'rhsa', 'title': 'RHSA-2025:11428'}, {'id': 'ALSA-2025:11428', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11428.html', 'type': 'self', 'title': 'ALSA-2025:11428'}], 'description': 'The kernel packages contain the Linux kernel, the core of any Linux operating system. \n\nSecurity Fix(es): \n\n * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)\n * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)\n * kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905)\n * kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry (CVE-2025-37958)\n * kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (CVE-2025-38089)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753056000000}, 'updated_date': {'$date': 1753863727000}, 'updateinfo_id': 'ALSA-2025:11428'} | c9fca3f28fd3a86c7a573b173dd79e5059d243b3e53331ee9547ea085ccf98c6 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27613 | ALSA-2025:11533 | git-gui | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 653b10145b0411f0692b1ae59200622b3ba5e82190e0d295b8e193619351f485 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48384 | ALSA-2025:11533 | git-gui | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 514781a0375e6d3cb9795c5d44b61134b93ff616b572de25a2a9741e7b30caa1 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48385 | ALSA-2025:11533 | git-gui | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | ecca41f04f8be0b9d78b96c27dd0ef2c5086c04dfd19a8d0d6bfe4e3afea4fef | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-50349 | ALSA-2025:11533 | git-gui | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | dcd38100dc0839bff34e32c169a9044135303707af5cb85f31057ef9bbe01099 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27614 | ALSA-2025:11533 | git-gui | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | ae05f86feb22fb54a2890f6c73381fc0494556f28b8133e9513ffd20ad6868ef | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-46835 | ALSA-2025:11533 | git-gui | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 3532539ede11e8f8f13a691dba8781de6f33fa8456bdd80e7aac5512d1e7b02b | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-52006 | ALSA-2025:11533 | git-gui | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | f4f4fb8a356cf91c09a9916baaa81259bacc97e2cb853c2e48690009caf36e4c | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27613 | ALSA-2025:11533 | perl-Git-SVN | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 857fc1ce53ea345bdcea1c9ae7558389de89e6807c7ef357fcc8ac8103ece783 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48384 | ALSA-2025:11533 | perl-Git-SVN | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 50b9ee83fb125602246d1662ae2a81b5a9327c8d0ff88004705833f5c5099ac4 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48385 | ALSA-2025:11533 | perl-Git-SVN | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 4c7142dddaec6082c2504848a6b9c23bf6e16c3c74bca32ad73fef16b13528c1 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-50349 | ALSA-2025:11533 | perl-Git-SVN | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | b415da8d0b6e45e0e3b8646594063011b07ea4fc49abb3380e66cee3d98c8b81 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27614 | ALSA-2025:11533 | perl-Git-SVN | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 188b94e7574a03d402165fcc87e900f94e5faded53ed0e4c0def192499ca36ac | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-46835 | ALSA-2025:11533 | perl-Git-SVN | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 7dcd465a5c043bfac2f3fcdc8be53f8785ef954a695717de94ffd57f2fae999d | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-52006 | ALSA-2025:11533 | perl-Git-SVN | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 2583eccc79db8ae72c89b3809a780f16a6fc3b576dd06b46d7459b871e585ffa | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27613 | ALSA-2025:11533 | gitweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | b512cdf0629a71c17e641c9476ebfe3ebafba5ad0b0ef9e76fdcb280b20689be | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48384 | ALSA-2025:11533 | gitweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | ac6325032d01fe3a34ae499c7f1548c49323bd24787736a89436eb441399de89 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48385 | ALSA-2025:11533 | gitweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 3a157473e40107529be0fa8d2a3ad94dc5b02bdfcda83777268511b41ed2f17d | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-50349 | ALSA-2025:11533 | gitweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 43a5917ca082b47371f77fc361c7a87b693e7667357a9d8e28877f67906f3464 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27614 | ALSA-2025:11533 | gitweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | b32bef26ddfe4616b331166ca571c4d6ec31fca38bec3c15a0b4d9f0d0e71ea4 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-46835 | ALSA-2025:11533 | gitweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 485682ff1794f3f2bee78f385551b6ccdb0f4ebb978cdd73babfbe91e7860bbe | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-52006 | ALSA-2025:11533 | gitweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | d2a06e712702357a3ac46083d10184331e94c404bbdaec4e2a585f306038e8df | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27613 | ALSA-2025:11533 | gitk | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | ea76ea8bc07da45aa953d1afd2d9d116e5406b9cdc8266703d5050187424b8b0 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48384 | ALSA-2025:11533 | gitk | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 62a844f58d1f9046c53b3181f8f9a942fb7e74bc9c5f937fd06a371e2486f8fb | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48385 | ALSA-2025:11533 | gitk | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 855f92de29eb0c229bbaf5283db70c2362397535e9d14dcf96931ec81a190d84 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-50349 | ALSA-2025:11533 | gitk | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | cdfbdba4d749cdd213ea1c83b16078c8be7f52a600e72bf08b02a1ae3b6436b4 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27614 | ALSA-2025:11533 | gitk | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 3c065a77bc437420cb796f1d8122067269b22cd759cba52725cc3fc430f3f729 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-46835 | ALSA-2025:11533 | gitk | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | b80d3b80abef71800d8ce1e2a07a6d3aa6d88cc3d308c6e1b360e9fa625714be | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-52006 | ALSA-2025:11533 | gitk | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | b77b610b5574afefc32eab75bd1fbdf18d9f4bf412e5c956bebf48f48de3bbcc | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27613 | ALSA-2025:11533 | git-core-doc | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 5b81655df9047c2fda482c8df64e4571b24683cf59212b0472c2dfa9e31c38c6 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48384 | ALSA-2025:11533 | git-core-doc | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 690d6d92c5678f74199f01cd0905a7a2907368fbe079dc8f2eb36bc8abda9eed | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48385 | ALSA-2025:11533 | git-core-doc | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 7c9f1e81a9c9ece0233d6c1502efdd767fef946b3e04a836280bc955172cf465 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-50349 | ALSA-2025:11533 | git-core-doc | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | ba2cb33291a187e3d93e1195124b784de2e605b57f800d5aab835628222fdc2c | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27614 | ALSA-2025:11533 | git-core-doc | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | a79dd5426e4cbb86750b6637a3b404cf3248ff633f44d03c088be61f105122d3 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-46835 | ALSA-2025:11533 | git-core-doc | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | cb2c27867786df44ff67d76a6f5f759cdcbb5a8bbb31c78c2f2c7f6241b59cb0 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-52006 | ALSA-2025:11533 | git-core-doc | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | c4babfe52f7f8525957f91d95080d54218ede8803f1bf92fe669bec690d6867e | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27613 | ALSA-2025:11533 | git-email | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 5e2c9c7dc4c7458509d7a824bc419826b80d37f4712234e27bf19af345067160 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48384 | ALSA-2025:11533 | git-email | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 48965213fcf6e13373eba74275752b1adc64d3bcff88651ea8b3a601cfc70dbe | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48385 | ALSA-2025:11533 | git-email | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 1315a62251b04a3608127ce714e905f430df2ea4a39eead136c8258ca8a78983 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-50349 | ALSA-2025:11533 | git-email | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 33a2d665e2ac8b34f91a1063dc2e045e83c6a01a117b113a86d5c982ca65a216 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27614 | ALSA-2025:11533 | git-email | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 8e835d326daffcea37fbac283b94ea2ecf88d572316fca7739707f5b9817c627 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-46835 | ALSA-2025:11533 | git-email | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | aff548036a5c837953b57fa33cfa46c2de9d0114dd51d09a5471910d2fb5fce5 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-52006 | ALSA-2025:11533 | git-email | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 5edc4f3afac6514d0744636551be35c4844920e1e41a0fab47a148715eb19c51 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-27613 | ALSA-2025:11533 | git-instaweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 5ac2b2ba0acbd74ca9b628ba53402d27793fc4154d836c428fb1ac7785fda684 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48384 | ALSA-2025:11533 | git-instaweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | cb08d2db0f2c2f6a4d24b9163dbf2e5ca2e26c0b81ad216046885b15cfcb2ed6 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2025-48385 | ALSA-2025:11533 | git-instaweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | 78e9dc7ca3ddfcc6517875565eeb81b5255487f8d5739be87f888c11ccfd0d6e | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 | |||
alma | alma/10/2025/ALSA-2025:11533.json | CVE-2024-50349 | ALSA-2025:11533 | git-instaweb | Important | 2.47.3-1.el10_0 | < 2.47.3-1.el10_0 | Important: git security update | {'_id': {}, 'type': 'security', 'title': 'Important: git security update', 'rights': 'Copyright 2025 AlmaLinux OS', 'status': 'final', 'fromstr': 'packager@almalinux.org', 'pkglist': {'name': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default', 'module': {}, 'packages': [{'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147', 'arch': 'noarch', 'name': 'git-gui', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-gui-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72', 'arch': 'noarch', 'name': 'perl-Git-SVN', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24', 'arch': 'noarch', 'name': 'gitweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1', 'arch': 'noarch', 'name': 'gitk', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'gitk-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949', 'arch': 'noarch', 'name': 'git-core-doc', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-core-doc-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f', 'arch': 'noarch', 'name': 'git-email', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-email-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce', 'arch': 'noarch', 'name': 'git-instaweb', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-instaweb-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': '934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09', 'arch': 'noarch', 'name': 'perl-Git', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'perl-Git-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306', 'arch': 'noarch', 'name': 'git-all', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-all-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb', 'arch': 'noarch', 'name': 'git-svn', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-svn-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}, {'src': 'git-2.47.3-1.el10_0.src.rpm', 'sum': 'd5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4', 'arch': 'noarch', 'name': 'git-subtree', 'epoch': '0', 'release': '1.el10_0', 'version': '2.47.3', 'filename': 'git-subtree-2.47.3-1.el10_0.noarch.rpm', 'sum_type': 5, 'reboot_suggested': 0}], 'shortname': 'almalinux-10-for-riscv64-appstream-rpms__10_0_default'}, 'release': '0', 'summary': 'git security update', 'version': '3', 'severity': 'Important', 'solution': 'For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258', 'pushcount': '1', 'bs_repo_id': {}, 'references': [{'id': 'RHSA-2025:11533', 'href': 'https://access.redhat.com/errata/RHSA-2025:11533', 'type': 'rhsa', 'title': 'RHSA-2025:11533'}, {'id': 'CVE-2024-50349', 'href': 'https://access.redhat.com/security/cve/CVE-2024-50349', 'type': 'cve', 'title': 'CVE-2024-50349'}, {'id': 'CVE-2024-52006', 'href': 'https://access.redhat.com/security/cve/CVE-2024-52006', 'type': 'cve', 'title': 'CVE-2024-52006'}, {'id': 'CVE-2025-27613', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27613', 'type': 'cve', 'title': 'CVE-2025-27613'}, {'id': 'CVE-2025-27614', 'href': 'https://access.redhat.com/security/cve/CVE-2025-27614', 'type': 'cve', 'title': 'CVE-2025-27614'}, {'id': 'CVE-2025-46835', 'href': 'https://access.redhat.com/security/cve/CVE-2025-46835', 'type': 'cve', 'title': 'CVE-2025-46835'}, {'id': 'CVE-2025-48384', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48384', 'type': 'cve', 'title': 'CVE-2025-48384'}, {'id': 'CVE-2025-48385', 'href': 'https://access.redhat.com/security/cve/CVE-2025-48385', 'type': 'cve', 'title': 'CVE-2025-48385'}, {'id': '2337824', 'href': 'https://bugzilla.redhat.com/2337824', 'type': 'bugzilla', 'title': ''}, {'id': '2337956', 'href': 'https://bugzilla.redhat.com/2337956', 'type': 'bugzilla', 'title': ''}, {'id': '2378806', 'href': 'https://bugzilla.redhat.com/2378806', 'type': 'bugzilla', 'title': ''}, {'id': '2378808', 'href': 'https://bugzilla.redhat.com/2378808', 'type': 'bugzilla', 'title': ''}, {'id': '2379124', 'href': 'https://bugzilla.redhat.com/2379124', 'type': 'bugzilla', 'title': ''}, {'id': '2379125', 'href': 'https://bugzilla.redhat.com/2379125', 'type': 'bugzilla', 'title': ''}, {'id': '2379326', 'href': 'https://bugzilla.redhat.com/2379326', 'type': 'bugzilla', 'title': ''}, {'id': 'ALSA-2025:11533', 'href': 'https://errata.almalinux.org/10/ALSA-2025-11533.html', 'type': 'self', 'title': 'ALSA-2025:11533'}], 'description': 'Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. \n\nSecurity Fix(es): \n\n * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349)\n * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006)\n * git: Git arbitrary code execution (CVE-2025-48384)\n * git: Git arbitrary file writes (CVE-2025-48385)\n * gitk: Git file creation flaw (CVE-2025-27613)\n * gitk: git script execution flaw (CVE-2025-27614)\n * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n', 'issued_date': {'$date': 1753142400000}, 'updated_date': {'$date': 1753349129000}, 'updateinfo_id': 'ALSA-2025:11533'} | b8480ee261b1fe2a6b8f54fc5839e35011e0ec430fa1b2f2e3484c4a2def9f48 | 2026-05-30 00:55:19.885834+03:00 | 2026-05-30 00:55:19.885834+03:00 |