Re: git: db727c902a8f - main - security/vuxml: Add devel/git-lfs entry

From: Dan Langille <dan_at_langille.org>
Date: Mon, 14 Sep 2026 17:12:27 UTC
On Mon, Sep 14, 2026, at 12:52 PM, Fernando Apesteguía wrote:
> The branch main has been updated by fernape:
>
> URL: 
> https://cgit.FreeBSD.org/ports/commit/?id=db727c902a8fa37ce530139e6cfaf2cfe50188ec
>
> commit db727c902a8fa37ce530139e6cfaf2cfe50188ec
> Author:     Ivo Marino <ivo.marino+freebsd@gmail.com>
> AuthorDate: 2026-09-14 16:51:05 +0000
> Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
> CommitDate: 2026-09-14 16:51:05 +0000
>
>     security/vuxml: Add devel/git-lfs entry
>    
>      * CVE-2025-26625
>    
>     PR:             298477
>     Reported by:    ivo.marino+freebsd@gmail.com
> ---
>  security/vuxml/vuln/2025.xml | 49 ++++++++++++++++++++++++++++++++++++++++++++
>  1 file changed, 49 insertions(+)
>
> diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml
> index 498ca0006391..fba992110302 100644
> --- a/security/vuxml/vuln/2025.xml
> +++ b/security/vuxml/vuln/2025.xml
> @@ -1,3 +1,52 @@
> +  <vuln vid="107f9dad-b05c-11f1-9369-b42e991fc52e">
> +    <topic>git-lfs -- Improper Link Resolution Before File 
> Access</topic>
> +    <affects>
> +    <package>
> +	<name>git-lfs</name>
> +	<range><lt>0.5.2, &amp;lt; 3.7.1</lt></range>


I'm no vuxml expert. Does the above need to be two separate entries?

> +    </package>
> +    </affects>
> +    <description>
> +	<body xmlns="http://www.w3.org/1999/xhtml">
> +	<p>https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5 
> reports:</p>
> +	<blockquote 
> cite="https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5">
> +	<p>
> +	Git LFS is a Git extension for versioning large files. In
> +	Git LFS versions 0.5.2 through 3.7.0, when populating a
> +	Git repository's working tree with the contents of Git LFS
> +	objects, certain Git LFS commands may write to files
> +	visible outside the current Git working tree if symbolic
> +	or hard links exist which collide with the paths of files
> +	tracked by Git LFS. The git lfs checkout and git lfs pull
> +	commands do not check for symbolic links before writing to
> +	files in the working tree, allowing an attacker to craft a
> +	repository containing symbolic or hard links that cause
> +	Git LFS to write to arbitrary file system locations
> +	accessible to the user running these commands. As well,
> +	when the git lfs checkout and git lfs pull commands are
> +	run in a bare repository, they could write to files
> +	visible outside the repository. The vulnerability is
> +	fixed in version 3.7.1. As a workaround, support for
> +	symlinks in Git may be disabled by setting the
> +	core.symlinks configuration option to false, after which
> +	further clones and fetches will not create symbolic links.
> +	However, any symbolic or hard links in existing
> +	repositories will still provide the opportunity for Git
> +	LFS to write to their targets.
> +	</p>
> +	</blockquote>
> +	</body>
> +    </description>
> +    <references>
> +      <cvename>CVE-2025-26625</cvename>
> +      <url>https://cveawg.mitre.org/api/cve/CVE-2025-26625</url>
> +    </references>
> +    <dates>
> +      <discovery>2025-10-17</discovery>
> +      <entry>2026-09-14</entry>
> +    </dates>
> +  </vuln>
> +
>    <vuln vid="963f4e9d-e4d5-11f0-984f-b42e991fc52e">
>      <topic>Forgejo -- Symbolic Link (Symlink) Following</topic>
>      <affects>

-- 
  Dan Langille
  dan@langille.org