OESA-2026-3623
Dashboard / Vulnerabilities / OESA-2026-3623
Summary: git security update
Details: Git is a free and open source distributed version control system designed to handle everything from small to very large projects with speed and efficiency. Git is easy to learn and has a tiny footprint with lightning fast performance. It outclasses SCM tools like Subversion, CVS, Perforce, and ClearCase with features like cheap local branching, convenient staging areas, and multiple workflows. Security Fix(es): Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are treated as local filesystem paths, and file URI prefixes are removed, so a bare UNC path or file URI targeting an attacker-controlled share causes Windows to initiate an outbound SMB connection. This can expose NTLM authentication material to the attacker-selected host. This issue is fixed in version 2.55.0.windows.4.(CVE-2026-62960)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3623, https://nvd.nist.gov/vuln/detail/CVE-2026-62960
Affected packages
Package
Name: git
Purl: pkg:rpm/openEuler/git&distro=openEuler-24.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
