Git Core Improvements and Contributions
Git security audit: Inside the hunt for - and discovery of - CVEs

Git security audit: Inside the hunt for - and discovery of - CVEs

1/24/2023 · Joern Schneeweisz

What this post added

This post details the discovery and root cause analysis of CVE-2022-41903, a heap corruption vulnerability in `git archive` related to `export-subst` and pretty format padding specifiers. It highlights the collaborative process involving GitLab, X41 D-Sec, and OSTIF, and mentions the contribution of GitLab's Gitaly team in developing fixes and extending Git's fuzzing harness.

Read the original post ↗