[ALSA-2025:11533] Important: git security update
Type:
security
Severity:
important
Release date:
2025-07-24
Description:
Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. Security Fix(es): * git: Git does not sanitize URLs when asking for credentials interactively (CVE-2024-50349) * git: Newline confusion in credential helpers can lead to credential exfiltration in git (CVE-2024-52006) * git: Git arbitrary code execution (CVE-2025-48384) * git: Git arbitrary file writes (CVE-2025-48385) * gitk: Git file creation flaw (CVE-2025-27613) * gitk: git script execution flaw (CVE-2025-27614) * git: Git GUI can create and overwrite files for which the user has write permission (CVE-2025-46835) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch git-gui-2.47.3-1.el10_0.noarch.rpm 1ddc3746ab181b75687c192d57a522284b6042b46727713358699f2ed009f147
noarch perl-Git-SVN-2.47.3-1.el10_0.noarch.rpm 21b6dc7fbfc8c031a7a3b2b04927bbfcbdcbd090ccc316f89472284e816bda72
noarch gitweb-2.47.3-1.el10_0.noarch.rpm 23d2b1db94ddd27d46c82479a53f3df13c755aac952eb0817e96b4a39b09dc24
noarch gitk-2.47.3-1.el10_0.noarch.rpm 45b3df6f789bdd8577a3cda2cabfe33d9d436b67ef01025b46453d25439e4bd1
noarch git-core-doc-2.47.3-1.el10_0.noarch.rpm 74ec60b957467d9c227b9503693515cf269aeecc5ccd030e1e02e5913c4e2949
noarch git-email-2.47.3-1.el10_0.noarch.rpm 8c6984e7dc61795c0870984cc9f56616b5ea2e74d31d9f795df350e7465cce7f
noarch git-instaweb-2.47.3-1.el10_0.noarch.rpm 9336710adff149893d5fb11465f959a725fb9a2d4c88e9911f579a3ebad5c4ce
noarch perl-Git-2.47.3-1.el10_0.noarch.rpm 934646f94c5315391d63ca73fefc0531bff234037a9006f559229915493a9f09
noarch git-all-2.47.3-1.el10_0.noarch.rpm d18356a77f1c0ea93db48cc41c978d11b621759efb33568d42448ef856940306
noarch git-svn-2.47.3-1.el10_0.noarch.rpm d3c0fcf8f98a83aab5ebed395f26b8fedc8742621c9a9c058c90921514c627bb
noarch git-subtree-2.47.3-1.el10_0.noarch.rpm d5cc2602c6b1745bb0817accb8a6f3adf42cd1df35802ccd94f74176f2a92bc4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.