CVE-2025-48384

high KEV
Published 2025-07-21 Β· Modified 2025-08-25
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
9.5

Description

Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.

CISA KEV

Vendor
Git
Product
Git
Due date
2025-09-15

Predictions

Exploit likelihood
99%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev β€” This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9 ; https://access.redhat.com/errata/RHSA-2025:13933 ; https://alas.aws.amazon.com/AL2/ALAS2-2025-2941.html ; https://linux.oracle.com/errata/ELSA-2025-11534.html ; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48384 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48384}

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed git-svn-2.47.3-1.el9_6.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1:2.47.3-0+deb13u1
sid Fixed 1:2.50.1-0.1
forky Fixed 1:2.50.1-0.1
bullseye Fixed 1:2.30.2-1+deb11u5
bookworm Fixed 1:2.39.5-0+deb12u3
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.