Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 42: git-lfs Critical Fix for Cross-Origin Bypass 2025-f8d1e1df04

fedora
Calendar Grey October 29, 2025
Dist Fedora Esm H88
Fix for multiple critical issues in git-lfs for Fedora 42, enhancing security against potential exploits and access.
Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625

Summary

Git Large File Storage (LFS) replaces large files such as audio samples,

videos, datasets, and graphics with text pointers inside Git, while

storing the file contents on a remote server.

Update Information:

Update to latest version (#2404637) Fix CVE-2025-47910, CVE-2025-47906, CVE-2025-26625

Change Log

* Mon Oct 20 2025 Elliott Sales de Andrade - 3.7.1-1 - Update to latest version (#2404637)

References


[ 1 ] Bug #2398691 - CVE-2025-47910 git-lfs: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398691 [ 2 ] Bug #2399372 - CVE-2025-47906 git-lfs: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399372 [ 3 ] Bug #2404637 - git-lfs-3.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2404637 [ 4 ] Bug #2404744 - CVE-2025-26625 git-lfs: Git LFS may write to arbitrary files via crafted symlinks [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2404744

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8d1e1df04' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: git-lfs
Product: Fedora 42
Version: 3.7.1
Release: 1.fc42
Summary: Git extension for versioning large files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here