Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

openSUSE 15-SP6: 2025:0153-1 moderate: git-lfs credential leak

opensuse
Calendar Grey May 12, 2025
Dist Opensuse Esm H88
An important patch for openSUSE tackling a significant flaw in git-lfs that affected the safeguarding of credentials.
An update that fixes one vulnerability is now available

Description

This update for git-lfs fixes the following issues:

Update to 3.6.1: (boo#1235876):

This release introduces a security fix for all platforms, which has been

assigned CVE-2024-53263.

When requesting credentials from Git for a remote host, prior versions

of Git LFS passed portions of the host's URL to the git-credential(1)

command without checking for embedded line-ending control characters, and

then sent any credentials received back from the Git credential helper to

the remote host. By inserting URL-encoded control characters such as line

feed (LF) or carriage return (CR) characters into the URL, an attacker

might have been able to retrieve a user's Git credentials. Git LFS now

prevents bare line feed (LF) characters from being included in the values

sent to the git-credential(1) command, and also prevents bare carriage

return (CR) characters from being included unless the

credential.protectProtocol configuration

option is set...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-153=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):

git-lfs-3.6.1-bp156.2.3.1

References

https://www.suse.com/security/cve/CVE-2024-53263.html

https://bugzilla.suse.com/1235876

Announcement ID: openSUSE-SU-2025:0153-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here