Upstream has released an update to address this: https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.2.1.txt New releases of existing, stable branches are available, too: https://www.kernel.org/pub/software/scm/git/ I set the severity at "medium" because Fedora defaults to a case-sensitive file system and is probably not vulnerable in that configuration.
*** This bug has been marked as a duplicate of bug 1175960 ***