AlmaLinux 9.2 [TuxCare] Security Update: git-lfs Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2025:1762539123)

critical Nessus Plugin ID 361151

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has a package installed that is affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2025:1762539123 advisory.

- Processing an incomplete post-handshake message for a QUIC connection can cause a panic. (CVE-2023-39321)

- QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size. (CVE-2023-39322)

- An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection. (CVE-2023-45288)

- A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop. (CVE-2024-24788)

- The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
(CVE-2024-24790)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected git-lfs package based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2025:1762539123.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2025:1762539123

http://www.nessus.org/u?00dafb65

Plugin Details

Severity: Critical

ID: 361151

File Name: tuxcare_alma_linux_9.2_CLSA-2025-1762539123.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.39

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-24790

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/7/2025

Vulnerability Publication Date: 9/7/2023

Reference Information

CVE: CVE-2023-39321, CVE-2023-39322, CVE-2023-45288, CVE-2024-24788, CVE-2024-24790, CVE-2024-34156

CLSA: 2025:1762539123