Critical Vulnerability Information Vulnerability Overview Type/Severity: Moderate Security Update Subject: Git LFS Security Update for Red Hat Enterprise Linux 9 Vulnerability Description Git Large File Storage (LFS) replaces large files (such as audio samples, videos, datasets, and graphics) by storing text pointers in Git and keeping the actual file contents on remote servers. Security Fixes : Panic occurs when processing post-handshake messages for QUIC connections (CVE-2023-39321) : Buffer for post-handshake messages lacks size restrictions (CVE-2023-39322) : Malicious DNS messages may cause infinite loops (CVE-2024-24786) : Unexpected behavior in ls method for IPv4-mapped IPv6 addresses (CVE-2024-24790) : Denial of service due to incorrect handling of 100-continue (CVE-2024-24791) : Golang FIPS zero buffer (CVE-2024-9355) Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 CVEs CVE-2023-39321 CVE-2023-39322 CVE-2024-9355 CVE-2024-24786 CVE-2024-24790 CVE-2024-24791 Solution For more details, see: https://access.redhat.com/articles/11258 References https://access.redhat.com/security/updates/classification/#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.6_release_notes/index