USN-7626-1

Source
https://ubuntu.com/security/notices/USN-7626-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7626-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7626-1
Upstream
Related
Published
2025-07-08T17:57:32.937129Z
Modified
2025-07-09T07:14:40.263384Z
Summary
git vulnerabilities
Details

Avi Halachmi discovered that Git incorrectly managed file modification constraints with Gitk. An attacker could possibly use this issue to create or write to arbitrary files on the system. (CVE-2025-27613)

Avi Halachmi discovered that Git incorrectly handled arguments when invoking the Gitk utility. If a user were tricked into cloning a malicious Git repository, an attacker could possibly use this issue to run arbitrary commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-27614)

Johannes Sixt discovered that Git incorrectly managed file modification constraints with Git GUI. If a user were tricked into editing a file in a malicious Git repository, an attacker could possibly use this issue to create or write to arbitrary files on the system. (CVE-2025-46835)

David Leadbeater discovered that Git incorrectly stripped CRLF characters when editing configuration files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-48384)

David Leadbeater discovered that Git incorrectly handled verification when fetching remote Git repositories. An attacker could possibly use this issue to perform protocol injection, leading to arbitrary code execution. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-48385)

David Leadbeater discovered that Git incorrectly handled memory with the wincred credential helper. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-48386)

References

Affected packages

Ubuntu:Pro:16.04:LTS / git

Package

Name
git
Purl
pkg:deb/ubuntu/git@1:2.7.4-0ubuntu1.10+esm9?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:2.7.4-0ubuntu1.10+esm9

Affected versions

1:2.*

1:2.5.0-1
1:2.6.2-1
1:2.6.3-1
1:2.6.4-1
1:2.7.0~rc3-1
1:2.7.0-1
1:2.7.3-0ubuntu1
1:2.7.4-0ubuntu1
1:2.7.4-0ubuntu1.1
1:2.7.4-0ubuntu1.2
1:2.7.4-0ubuntu1.3
1:2.7.4-0ubuntu1.4
1:2.7.4-0ubuntu1.5
1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.7
1:2.7.4-0ubuntu1.8
1:2.7.4-0ubuntu1.9
1:2.7.4-0ubuntu1.10
1:2.7.4-0ubuntu1.10+esm1
1:2.7.4-0ubuntu1.10+esm3
1:2.7.4-0ubuntu1.10+esm4
1:2.7.4-0ubuntu1.10+esm5
1:2.7.4-0ubuntu1.10+esm6
1:2.7.4-0ubuntu1.10+esm7
1:2.7.4-0ubuntu1.10+esm8

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-arch",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-core",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-doc",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / git

Package

Name
git
Purl
pkg:deb/ubuntu/git@1:2.17.1-1ubuntu0.18+esm2?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:2.17.1-1ubuntu0.18+esm2

Affected versions

1:2.*

1:2.14.1-1ubuntu4
1:2.15.1-1ubuntu2
1:2.17.0-1ubuntu1
1:2.17.1-1ubuntu0.1
1:2.17.1-1ubuntu0.3
1:2.17.1-1ubuntu0.4
1:2.17.1-1ubuntu0.5
1:2.17.1-1ubuntu0.6
1:2.17.1-1ubuntu0.7
1:2.17.1-1ubuntu0.8
1:2.17.1-1ubuntu0.9
1:2.17.1-1ubuntu0.10
1:2.17.1-1ubuntu0.11
1:2.17.1-1ubuntu0.12
1:2.17.1-1ubuntu0.13
1:2.17.1-1ubuntu0.14
1:2.17.1-1ubuntu0.15
1:2.17.1-1ubuntu0.16
1:2.17.1-1ubuntu0.17
1:2.17.1-1ubuntu0.18
1:2.17.1-1ubuntu0.18+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-dbgsym",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-doc",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / git

Package

Name
git
Purl
pkg:deb/ubuntu/git@1:2.25.1-1ubuntu3.14+esm1?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:2.25.1-1ubuntu3.14+esm1

Affected versions

1:2.*

1:2.20.1-2ubuntu1
1:2.24.0-1ubuntu1
1:2.24.0-1ubuntu2
1:2.25.0-1ubuntu1
1:2.25.1-1ubuntu1
1:2.25.1-1ubuntu2
1:2.25.1-1ubuntu3
1:2.25.1-1ubuntu3.1
1:2.25.1-1ubuntu3.2
1:2.25.1-1ubuntu3.3
1:2.25.1-1ubuntu3.4
1:2.25.1-1ubuntu3.5
1:2.25.1-1ubuntu3.6
1:2.25.1-1ubuntu3.7
1:2.25.1-1ubuntu3.8
1:2.25.1-1ubuntu3.10
1:2.25.1-1ubuntu3.11
1:2.25.1-1ubuntu3.12
1:2.25.1-1ubuntu3.13
1:2.25.1-1ubuntu3.14

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-dbgsym",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-doc",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        }
    ]
}

Ubuntu:22.04:LTS / git

Package

Name
git
Purl
pkg:deb/ubuntu/git@1:2.34.1-1ubuntu1.13?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:2.34.1-1ubuntu1.13

Affected versions

1:2.*

1:2.32.0-1ubuntu1
1:2.33.1-1ubuntu1
1:2.34.1-1ubuntu1
1:2.34.1-1ubuntu1.1
1:2.34.1-1ubuntu1.2
1:2.34.1-1ubuntu1.4
1:2.34.1-1ubuntu1.5
1:2.34.1-1ubuntu1.6
1:2.34.1-1ubuntu1.8
1:2.34.1-1ubuntu1.9
1:2.34.1-1ubuntu1.10
1:2.34.1-1ubuntu1.11
1:2.34.1-1ubuntu1.12

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-dbgsym",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-doc",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        }
    ]
}

Ubuntu:24.10 / git

Package

Name
git
Purl
pkg:deb/ubuntu/git@1:2.45.2-1ubuntu1.2?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:2.45.2-1ubuntu1.2

Affected versions

1:2.*

1:2.43.0-1ubuntu7
1:2.45.1-1ubuntu1
1:2.45.2-1ubuntu1
1:2.45.2-1ubuntu1.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-dbgsym",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-doc",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.45.2-1ubuntu1.2"
        }
    ]
}

Ubuntu:24.04:LTS / git

Package

Name
git
Purl
pkg:deb/ubuntu/git@1:2.43.0-1ubuntu7.3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:2.43.0-1ubuntu7.3

Affected versions

1:2.*

1:2.40.1-1ubuntu1
1:2.43.0-1ubuntu1
1:2.43.0-1ubuntu5
1:2.43.0-1ubuntu6
1:2.43.0-1ubuntu7
1:2.43.0-1ubuntu7.1
1:2.43.0-1ubuntu7.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-dbgsym",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-doc",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        }
    ]
}

Ubuntu:25.04 / git

Package

Name
git
Purl
pkg:deb/ubuntu/git@1:2.48.1-0ubuntu1.1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:2.48.1-0ubuntu1.1

Affected versions

1:2.*

1:2.45.2-1ubuntu1
1:2.45.2-1.2ubuntu1
1:2.47.1-0ubuntu1
1:2.47.1-1ubuntu1
1:2.48.1-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-dbgsym",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-doc",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        }
    ]
}