Important: git-lfs security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7005", "synopsis": "Important: git-lfs security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for git-lfs.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-04-10T12:07:15.128312Z", "rpms": {"Rocky Linux 10": {"nvras": ["git-lfs-debugsource-0:3.6.1-8.el10_1.ppc64le.rpm", "git-lfs-0:3.6.1-8.el10_1.s390x.rpm", "git-lfs-0:3.6.1-8.el10_1.x86_64.rpm", "git-lfs-debuginfo-0:3.6.1-8.el10_1.s390x.rpm", "git-lfs-debuginfo-0:3.6.1-8.el10_1.ppc64le.rpm", "git-lfs-debuginfo-0:3.6.1-8.el10_1.aarch64.rpm", "git-lfs-0:3.6.1-8.el10_1.src.rpm", "git-lfs-0:3.6.1-8.el10_1.aarch64.rpm", "git-lfs-0:3.6.1-8.el10_1.ppc64le.rpm", "git-lfs-debugsource-0:3.6.1-8.el10_1.s390x.rpm", "git-lfs-debugsource-0:3.6.1-8.el10_1.aarch64.rpm", "git-lfs-debuginfo-0:3.6.1-8.el10_1.x86_64.rpm","git-lfs-debugsource-0:3.6.1-8.el10_1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. That provides a critical security update for git-lfs on Rocky Linux 10 including CVE-2026-25679 details and solutions.. Git Large File Storage, Rocky Linux 10, Git security update. . Severity: Important. LinuxSecurity.com Team
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1087-1
Get the latest Linux and open source security news straight to your inbox.