Skip to content

feat: update git to 1:2.53.0-1 (CVE fixes) - #8

Open
deepin-ci-robot wants to merge 1 commit into
masterfrom
cve/git-2.53.0-upgrade
Open

feat: update git to 1:2.53.0-1 (CVE fixes)#8
deepin-ci-robot wants to merge 1 commit into
masterfrom
cve/git-2.53.0-upgrade

Conversation

@deepin-ci-robot

Copy link
Copy Markdown
Contributor

Summary

Update git to upstream version 1:2.53.0-1 from Debian sid.

CVE Fixes

This update includes the following CVE fixes (already applied in 2.50.1):

CVE ID Severity Description
CVE-2025-27613 High gitk: file creation/truncation after cloning untrusted repository
CVE-2025-27614 High gitk: user can be tricked into running any script after cloning untrusted repository
CVE-2025-46835 High git-gui: file creation/overwriting after cloning untrusted repository
CVE-2025-48384 High script execution after cloning untrusted repository
CVE-2025-48385 Medium protocol injection when fetching

Changes

  • New upstream release 2.53.0
  • Updated debian directory from Debian sid
  • Preserved deepin specific configurations

Testing

  • Source package builds successfully
  • Debian changelog format verified

Upstream: https://github.com/git/git/releases/tag/v2.53.0

New upstream release with security updates and bug fixes.

CVE fixes included (already in 2.50.1):
- CVE-2025-27613: gitk file creation/truncation vulnerability
- CVE-2025-27614: gitk script execution vulnerability
- CVE-2025-46835: git-gui file creation/overwriting vulnerability
- CVE-2025-48384: script execution after cloning
- CVE-2025-48385: protocol injection when fetching

Upstream: https://github.com/git/git/releases/tag/v2.53.0
@deepin-ci-robot
deepin-ci-robot requested a review from myml April 16, 2026 21:57
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign xzl01 for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions

Copy link
Copy Markdown

TAG Bot

TAG: 1%2.53.0-1
EXISTED: no
DISTRIBUTION: unstable

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants