Re: git: db727c902a8f - main - security/vuxml: Add devel/git-lfs entry
Date: Mon, 14 Sep 2026 17:12:27 UTC
On Mon, Sep 14, 2026, at 12:52 PM, Fernando Apesteguía wrote: > The branch main has been updated by fernape: > > URL: > https://cgit.FreeBSD.org/ports/commit/?id=db727c902a8fa37ce530139e6cfaf2cfe50188ec > > commit db727c902a8fa37ce530139e6cfaf2cfe50188ec > Author: Ivo Marino <ivo.marino+freebsd@gmail.com> > AuthorDate: 2026-09-14 16:51:05 +0000 > Commit: Fernando Apesteguía <fernape@FreeBSD.org> > CommitDate: 2026-09-14 16:51:05 +0000 > > security/vuxml: Add devel/git-lfs entry > > * CVE-2025-26625 > > PR: 298477 > Reported by: ivo.marino+freebsd@gmail.com > --- > security/vuxml/vuln/2025.xml | 49 ++++++++++++++++++++++++++++++++++++++++++++ > 1 file changed, 49 insertions(+) > > diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml > index 498ca0006391..fba992110302 100644 > --- a/security/vuxml/vuln/2025.xml > +++ b/security/vuxml/vuln/2025.xml > @@ -1,3 +1,52 @@ > + <vuln vid="107f9dad-b05c-11f1-9369-b42e991fc52e"> > + <topic>git-lfs -- Improper Link Resolution Before File > Access</topic> > + <affects> > + <package> > + <name>git-lfs</name> > + <range><lt>0.5.2, &lt; 3.7.1</lt></range> I'm no vuxml expert. Does the above need to be two separate entries? > + </package> > + </affects> > + <description> > + <body xmlns="http://www.w3.org/1999/xhtml"> > + <p>https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5 > reports:</p> > + <blockquote > cite="https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5"> > + <p> > + Git LFS is a Git extension for versioning large files. In > + Git LFS versions 0.5.2 through 3.7.0, when populating a > + Git repository's working tree with the contents of Git LFS > + objects, certain Git LFS commands may write to files > + visible outside the current Git working tree if symbolic > + or hard links exist which collide with the paths of files > + tracked by Git LFS. The git lfs checkout and git lfs pull > + commands do not check for symbolic links before writing to > + files in the working tree, allowing an attacker to craft a > + repository containing symbolic or hard links that cause > + Git LFS to write to arbitrary file system locations > + accessible to the user running these commands. As well, > + when the git lfs checkout and git lfs pull commands are > + run in a bare repository, they could write to files > + visible outside the repository. The vulnerability is > + fixed in version 3.7.1. As a workaround, support for > + symlinks in Git may be disabled by setting the > + core.symlinks configuration option to false, after which > + further clones and fetches will not create symbolic links. > + However, any symbolic or hard links in existing > + repositories will still provide the opportunity for Git > + LFS to write to their targets. > + </p> > + </blockquote> > + </body> > + </description> > + <references> > + <cvename>CVE-2025-26625</cvename> > + <url>https://cveawg.mitre.org/api/cve/CVE-2025-26625</url> > + </references> > + <dates> > + <discovery>2025-10-17</discovery> > + <entry>2026-09-14</entry> > + </dates> > + </vuln> > + > <vuln vid="963f4e9d-e4d5-11f0-984f-b42e991fc52e"> > <topic>Forgejo -- Symbolic Link (Symlink) Following</topic> > <affects> -- Dan Langille dan@langille.org