openSUSE-SU-2026:21558-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21558-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21558-1
Upstream
CVE (5)
Related
Published
2026-08-10T13:10:07Z
Modified
2026-08-12T18:23:52Z
Summary
Security update for gitoxide
Details

This update for gitoxide fixes the following issues:

Changes in gitoxide:

  • Update to 0.56.0:

    • Fixes CVE-2026-40034 (boo#1266434): the CommandForbiddenInModules trust check could be bypassed in gix_submodule::File::update(), which allowed arbitrary command execution from a crafted .gitmodules file
    • Fixes a submodule name validation bypass that allowed traversal out of .git/modules and disclosure of credentials
    • Fixes symlinked .gitmodules files being followed and parsed from outside the repository
    • Fixes several denial-of-service vectors in gix-pack: unchecked indexing panics and uncapped allocations from crafted pack data
    • Fixes HTTP credentials being leaked to the redirected host by the curl transport backend
    • Add the gix config show, gix config list, gix config fmt, gix free remote refs, gix free trust, gix dirwalk and gix tix subcommands
    • Add a gix status --untracked flag and gix merge tree --message for creating commits
    • gix exclude query is now index-aware and no longer reports ignore matches for tracked files, matching git check-ignore
    • Preserve all configured remote URLs rather than only the last one
    • Fix fetching and cloning with tag refspecs in shallow clones, relative worktree linking files and loose ref path-prefix collisions
    • Update the crates to the Rust 2024 edition
  • Refresh the vendored dependencies. Recording the state of the remaining open CVE bugs against this version, none of which it is affected by:

    • CVE-2026-25541 (boo#1274525): the vendored bytes is now 1.12.1, above the 1.11.1 fix
    • CVE-2025-22620 (boo#1236139): gix-worktree-state is 0.33.0, far above the 0.17.0 that fixed the world-writable checkout of executable files
  • update to 0.50.0: see https://github.com/GitoxideLabs/gitoxide/compare/v0.42.0...v0.50.0

  • update to 0.42.0:

    • add first 'debug' version of gix diff file
    • use revspecs for revision and path
    • CVE-2025-31130: use collision-detecting SHA-1 hash boo#1240872
  • Update to version 0.41.0:

    • add gix blame -L start,end
    • add gix env to print paths relevant to the Git installation.
    • Document the remaining subcommands
    • Add support for statistics and additional performance information.
    • add gix blame to the CLI. That way it's possible to see the blame result of any file in the repository.
  • Updates from version 0.40.0:

    • add first 'debug' version of gix log. It's primarily meant to better understand gix blame.
    • add --tree-favor to gix merge tree|commit. With it one can decide which side to favor in case of irreconcilable tree-conflicts.
    • CVE-2025-22620: gix-worktree-state specifies 0777 permissions when checking out executable files (boo#1236139)
  • Update to version 0.39.0: New Features

    • add gix merge commit --debug
    • add gix merge commits
    • add gix merge tree to merge trees similarly to git merge-tree.
  • Update to version 0.38.0: New Features

    • support for listing worktrees with gix worktree list
    • add first 'debug' version of gix diff tree.
    • add new gix cat command.
    • add gix merge-file with similar features as git merge-file
    • gix merge-base for the CLI Bug Fixes
    • Adjust gix clean warning and help for worktree fix
    • Clarify -r/--repositories and --skip-hidden-repositories Other
    • switch from time to jiff
    • Unify style in config support info
References

Affected packages

openSUSE:Leap 16.0 / gitoxide

Package

Name
gitoxide
Purl
pkg:rpm/opensuse/gitoxide&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.56.0-bp160.1.1

Ecosystem specific

{
    "binaries": [
        {
            "gitoxide": "0.56.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21558-1.json"