Multiple security vulnerabilities affect the git-lfs package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.