| Name | CVE-2025-48384 |
| Description | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-4323-1 |
| Debian Bugs | 1108983 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| git (PTS) | bullseye | 1:2.30.2-1+deb11u2 | vulnerable |
| bullseye (security) | 1:2.30.2-1+deb11u5 | fixed | |
| bookworm, bookworm (security) | 1:2.39.5-0+deb12u2 | vulnerable | |
| trixie | 1:2.47.3-0+deb13u1 | fixed | |
| forky, sid | 1:2.51.0-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| git | source | bullseye | 1:2.30.2-1+deb11u5 | DLA-4323-1 | ||
| git | source | trixie | 1:2.47.3-0+deb13u1 | |||
| git | source | (unstable) | 1:2.50.1-0.1 | 1108983 |
[bookworm] - git <no-dsa> (Will be fixed in point release)
https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9
https://lore.kernel.org/git/xmqq5xg2wrd1.fsf@gitster.g/
Fixed by: https://github.com/git/git/commit/05e9cd64ee23bbadcea6bcffd6660ed02b8eab89 (2.43.7)