Avi Halachmi discovered that Git incorrectly managed file modification constraints with Gitk. An attacker could possibly use this issue to create or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when invoking the Gitk utility. If a user were tricked into cloning a malicious Git repository, an attacker could possibly use this issue to run arbitrary commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-27614)
Johannes Sixt discovered that Git incorrectly managed file modification constraints with Git GUI. If a user were tricked into editing a file in a malicious Git repository, an attacker could possibly use this issue to create or write to arbitrary files on the system. (CVE-2025-46835)
David Leadbeater discovered that Git incorrectly stripped CRLF characters when editing configuration files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-48384)
David Leadbeater discovered that Git incorrectly handled verification when fetching remote Git repositories. An attacker could possibly use this issue to perform protocol injection, leading to arbitrary code execution. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-48385)
David Leadbeater discovered that Git incorrectly handled memory with the wincred credential helper. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-48386)
{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.34.1-1ubuntu1.13"
        }
    ]
}{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-48384"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48386"
        }
    ]
}
                          {
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.43.0-1ubuntu7.3"
        }
    ]
}{
    "ecosystem": "Ubuntu:24.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-27613"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-27614"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-46835"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-48384"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48385"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48386"
        }
    ]
}
                          {
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.48.1-0ubuntu1.1"
        }
    ]
}{
    "ecosystem": "Ubuntu:25.04",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-27613"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-27614"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-46835"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-48384"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48385"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48386"
        }
    ]
}
                          {
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-arch",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-core",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.7.4-0ubuntu1.10+esm9"
        }
    ]
}{
    "ecosystem": "Ubuntu:Pro:16.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-48384"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48386"
        }
    ]
}
                          {
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.17.1-1ubuntu0.18+esm2"
        }
    ]
}{
    "ecosystem": "Ubuntu:Pro:18.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-48384"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48386"
        }
    ]
}
                          {
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "git",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-all",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-cvs",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-daemon-run",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-daemon-sysvinit",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-el",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-email",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-gui",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-man",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-mediawiki",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "git-svn",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "gitk",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        },
        {
            "binary_name": "gitweb",
            "binary_version": "1:2.25.1-1ubuntu3.14+esm1"
        }
    ]
}{
    "ecosystem": "Ubuntu:Pro:20.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-48384"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-48386"
        }
    ]
}