git: db727c902a8f - main - security/vuxml: Add devel/git-lfs entry

From: Fernando Apesteguía <fernape_at_FreeBSD.org>
Date: Mon, 14 Sep 2026 16:52:16 UTC
The branch main has been updated by fernape:

URL: https://cgit.FreeBSD.org/ports/commit/?id=db727c902a8fa37ce530139e6cfaf2cfe50188ec

commit db727c902a8fa37ce530139e6cfaf2cfe50188ec
Author:     Ivo Marino <ivo.marino+freebsd@gmail.com>
AuthorDate: 2026-09-14 16:51:05 +0000
Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2026-09-14 16:51:05 +0000

    security/vuxml: Add devel/git-lfs entry
    
     * CVE-2025-26625
    
    PR:             298477
    Reported by:    ivo.marino+freebsd@gmail.com
---
 security/vuxml/vuln/2025.xml | 49 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 49 insertions(+)

diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml
index 498ca0006391..fba992110302 100644
--- a/security/vuxml/vuln/2025.xml
+++ b/security/vuxml/vuln/2025.xml
@@ -1,3 +1,52 @@
+  <vuln vid="107f9dad-b05c-11f1-9369-b42e991fc52e">
+    <topic>git-lfs -- Improper Link Resolution Before File Access</topic>
+    <affects>
+    <package>
+	<name>git-lfs</name>
+	<range><lt>0.5.2, &amp;lt; 3.7.1</lt></range>
+    </package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5 reports:</p>
+	<blockquote cite="https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5">
+	<p>
+	Git LFS is a Git extension for versioning large files. In
+	Git LFS versions 0.5.2 through 3.7.0, when populating a
+	Git repository's working tree with the contents of Git LFS
+	objects, certain Git LFS commands may write to files
+	visible outside the current Git working tree if symbolic
+	or hard links exist which collide with the paths of files
+	tracked by Git LFS. The git lfs checkout and git lfs pull
+	commands do not check for symbolic links before writing to
+	files in the working tree, allowing an attacker to craft a
+	repository containing symbolic or hard links that cause
+	Git LFS to write to arbitrary file system locations
+	accessible to the user running these commands. As well,
+	when the git lfs checkout and git lfs pull commands are
+	run in a bare repository, they could write to files
+	visible outside the repository. The vulnerability is
+	fixed in version 3.7.1. As a workaround, support for
+	symlinks in Git may be disabled by setting the
+	core.symlinks configuration option to false, after which
+	further clones and fetches will not create symbolic links.
+	However, any symbolic or hard links in existing
+	repositories will still provide the opportunity for Git
+	LFS to write to their targets.
+	</p>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2025-26625</cvename>
+      <url>https://cveawg.mitre.org/api/cve/CVE-2025-26625</url>
+    </references>
+    <dates>
+      <discovery>2025-10-17</discovery>
+      <entry>2026-09-14</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="963f4e9d-e4d5-11f0-984f-b42e991fc52e">
     <topic>Forgejo -- Symbolic Link (Symlink) Following</topic>
     <affects>