Name | CVE-2025-48384 |
Description | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 1108983 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
git (PTS) | bullseye | 1:2.30.2-1+deb11u2 | vulnerable |
bullseye (security) | 1:2.30.2-1+deb11u4 | vulnerable | |
bookworm, bookworm (security) | 1:2.39.5-0+deb12u2 | vulnerable | |
trixie | 1:2.47.2-0.2 | vulnerable | |
sid | 1:2.50.0-1 | vulnerable |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
git | source | (unstable) | (unfixed) | 1108983 |
https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9
https://lore.kernel.org/git/xmqq5xg2wrd1.fsf@gitster.g/
Fixed by: https://github.com/git/git/commit/05e9cd64ee23bbadcea6bcffd6660ed02b8eab89 (2.43.7)