git: db727c902a8f - main - security/vuxml: Add devel/git-lfs entry
Date: Mon, 14 Sep 2026 16:52:16 UTC
The branch main has been updated by fernape:
URL: https://cgit.FreeBSD.org/ports/commit/?id=db727c902a8fa37ce530139e6cfaf2cfe50188ec
commit db727c902a8fa37ce530139e6cfaf2cfe50188ec
Author: Ivo Marino <ivo.marino+freebsd@gmail.com>
AuthorDate: 2026-09-14 16:51:05 +0000
Commit: Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2026-09-14 16:51:05 +0000
security/vuxml: Add devel/git-lfs entry
* CVE-2025-26625
PR: 298477
Reported by: ivo.marino+freebsd@gmail.com
---
security/vuxml/vuln/2025.xml | 49 ++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 49 insertions(+)
diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml
index 498ca0006391..fba992110302 100644
--- a/security/vuxml/vuln/2025.xml
+++ b/security/vuxml/vuln/2025.xml
@@ -1,3 +1,52 @@
+ <vuln vid="107f9dad-b05c-11f1-9369-b42e991fc52e">
+ <topic>git-lfs -- Improper Link Resolution Before File Access</topic>
+ <affects>
+ <package>
+ <name>git-lfs</name>
+ <range><lt>0.5.2, &lt; 3.7.1</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5 reports:</p>
+ <blockquote cite="https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5">
+ <p>
+ Git LFS is a Git extension for versioning large files. In
+ Git LFS versions 0.5.2 through 3.7.0, when populating a
+ Git repository's working tree with the contents of Git LFS
+ objects, certain Git LFS commands may write to files
+ visible outside the current Git working tree if symbolic
+ or hard links exist which collide with the paths of files
+ tracked by Git LFS. The git lfs checkout and git lfs pull
+ commands do not check for symbolic links before writing to
+ files in the working tree, allowing an attacker to craft a
+ repository containing symbolic or hard links that cause
+ Git LFS to write to arbitrary file system locations
+ accessible to the user running these commands. As well,
+ when the git lfs checkout and git lfs pull commands are
+ run in a bare repository, they could write to files
+ visible outside the repository. The vulnerability is
+ fixed in version 3.7.1. As a workaround, support for
+ symlinks in Git may be disabled by setting the
+ core.symlinks configuration option to false, after which
+ further clones and fetches will not create symbolic links.
+ However, any symbolic or hard links in existing
+ repositories will still provide the opportunity for Git
+ LFS to write to their targets.
+ </p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2025-26625</cvename>
+ <url>https://cveawg.mitre.org/api/cve/CVE-2025-26625</url>
+ </references>
+ <dates>
+ <discovery>2025-10-17</discovery>
+ <entry>2026-09-14</entry>
+ </dates>
+ </vuln>
+
<vuln vid="963f4e9d-e4d5-11f0-984f-b42e991fc52e">
<topic>Forgejo -- Symbolic Link (Symlink) Following</topic>
<affects>