Git Large File Storage (LFS) replaces large files such as audio samples,
videos, datasets, and graphics with text pointers inside Git, while
storing the file contents on a remote server.
Update Information:
Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625
* Mon Oct 20 2025 Elliott Sales de Andrade
[ 1 ] Bug #2398691 - CVE-2025-47910 git-lfs: CrossOriginProtection bypass in net/http [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2398691
[ 2 ] Bug #2399372 - CVE-2025-47906 git-lfs: Unexpected paths returned from LookPath in os/exec [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2399372
[ 3 ] Bug #2404637 - git-lfs-3.7.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2404637
[ 4 ] Bug #2404744 - CVE-2025-26625 git-lfs: Git LFS may write to arbitrary files via crafted symlinks [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2404744
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8d1e1df04' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.