Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:19715: Important: git-lfs security update

  • What: Important security update for git-lfs
  • Impact: Red Hat Enterprise Linux 10.0 users should apply the update to address security vulnerabilities
Read Full Article →

Red Hat Product Errata RHSA-2026:19715 - Security Advisory Issued: 2026-05-20 Updated: 2026-05-20 RHSA-2026:19715 - Security Advisory Overview Updated Packages Synopsis Important: git-lfs security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for git-lfs is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVEs CVE-2026-32280 CVE-2026-32282 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e x86_64 git-lfs-3.6.1-2.el10_0.4.x86_64.rpm SHA-256: 30994b7df5cb18f3d7cf98f4945117991f985d4f9ced848f13c6547b11cb8bd3 git-lfs-debuginfo-3.6.1-2.el10_0.4.x86_64.rpm SHA-256: ce3e2051bd2026fd371fbf47ca0ffe945f2320a903bdcce52e9e50c24f8740be git-lfs-debugsource-3.6.1-2.el10_0.4.x86_64.rpm SHA-256: 045648c38fbfb53f0a0de879aed830dfb76247ce40b1fda94f2622c0385d051d Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e s390x git-lfs-3.6.1-2.el10_0.4.s390x.rpm SHA-256: 15c49d07927b7235069bfccffff9a495ac3e4ef083786046597c60f674e6d88f git-lfs-debuginfo-3.6.1-2.el10_0.4.s390x.rpm SHA-256: 1035228ad1efb1e1d0a666f55bd83db9d7c2925f02ec447109193d02418cf80e git-lfs-debugsource-3.6.1-2.el10_0.4.s390x.rpm SHA-256: 0ce96bcff4ab213e5d296ed56bd98bfe82ea4f75be2c5bc8a8b6d63ce85c6565 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e ppc64le git-lfs-3.6.1-2.el10_0.4.ppc64le.rpm SHA-256: 13f4caaaedfb3477274a300b33c28442627a4401c656dda23a94addb00bc5c4b git-lfs-debuginfo-3.6.1-2.el10_0.4.ppc64le.rpm SHA-256: 21a5643d8cc1f3855f368bd861e3be23876bec25302f198cb515d81b48b5c4b3 git-lfs-debugsource-3.6.1-2.el10_0.4.ppc64le.rpm SHA-256: 8b33b8e65253d65b01f3d449dd6d1d2bd4a8184c26a62406b1c972dcfbd5c014 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e aarch64 git-lfs-3.6.1-2.el10_0.4.aarch64.rpm SHA-256: fc5b66e3c7e2958b6d2d7a36f96aa3dfbfca709b83ae504b022af5aea88d0d90 git-lfs-debuginfo-3.6.1-2.el10_0.4.aarch64.rpm SHA-256: 0eb5aaa13d1526ee8d0798a4681b7bacd168586b9b3bc863d55bc29208de6d6b git-lfs-debugsource-3.6.1-2.el10_0.4.aarch64.rpm SHA-256: 59c2055f7d306e560950d7eb401cc5623a3a72491eef12549dac336b316e9311 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e aarch64 git-lfs-3.6.1-2.el10_0.4.aarch64.rpm SHA-256: fc5b66e3c7e2958b6d2d7a36f96aa3dfbfca709b83ae504b022af5aea88d0d90 git-lfs-debuginfo-3.6.1-2.el10_0.4.aarch64.rpm SHA-256: 0eb5aaa13d1526ee8d0798a4681b7bacd168586b9b3bc863d55bc29208de6d6b git-lfs-debugsource-3.6.1-2.el10_0.4.aarch64.rpm SHA-256: 59c2055f7d306e560950d7eb401cc5623a3a72491eef12549dac336b316e9311 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e s390x git-lfs-3.6.1-2.el10_0.4.s390x.rpm SHA-256: 15c49d07927b7235069bfccffff9a495ac3e4ef083786046597c60f674e6d88f git-lfs-debuginfo-3.6.1-2.el10_0.4.s390x.rpm SHA-256: 1035228ad1efb1e1d0a666f55bd83db9d7c2925f02ec447109193d02418cf80e git-lfs-debugsource-3.6.1-2.el10_0.4.s390x.rpm SHA-256: 0ce96bcff4ab213e5d296ed56bd98bfe82ea4f75be2c5bc8a8b6d63ce85c6565 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e ppc64le git-lfs-3.6.1-2.el10_0.4.ppc64le.rpm SHA-256: 13f4caaaedfb3477274a300b33c28442627a4401c656dda23a94addb00bc5c4b git-lfs-debuginfo-3.6.1-2.el10_0.4.ppc64le.rpm SHA-256: 21a5643d8cc1f3855f368bd861e3be23876bec25302f198cb515d81b48b5c4b3 git-lfs-debugsource-3.6.1-2.el10_0.4.ppc64le.rpm SHA-256: 8b33b8e65253d65b01f3d449dd6d1d2bd4a8184c26a62406b1c972dcfbd5c014 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM git-lfs-3.6.1-2.el10_0.4.src.rpm SHA-256: 729c99c8c4750c245fc92bedb8addcf2ed56586db364d3864caf68131956167e x86_64 git-lfs-3.6.1-2.el10_0.4.x86_64.rpm SHA-256: 30994b7df5cb18f3d7cf98f4945117991f985d4f9ced848f13c6547b11cb8bd3 git-lfs-debuginfo-3.6.1-2.el10_0.4.x86_64.rpm SHA-256: ce3e2051bd2026fd371fbf47ca0ffe945f2320a903bdcce52e9e50c24f8740be git-lfs-debugsource-3.6.1-2.el10_0.4.x86_64.rpm SHA-256: 045648c38fbfb53f0a0de879aed830dfb76247ce40b1fda94f2622c0385d051d The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article