CVE-2025-48384

high KEV
Published 2025-07-21 · Modified 2025-07-22
CVSS v3
CVSS v2
VIR risk
9.5

Description

Important: git security update

CISA KEV

Vendor
Git
Product
Git
Due date
2025-09-15

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2025-11462.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-11534.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2379326

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2379125

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2379124

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2378808

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2378806

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2337956

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2337824

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:11534

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9 ; https://access.redhat.com/errata/RHSA-2025:13933 ; https://alas.aws.amazon.com/AL2/ALAS2-2025-2941.html ; https://linux.oracle.com/errata/ELSA-2025-11534.html ; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48384 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48384

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:11462

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-48384.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-48384

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:11534

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2025:11462

Exploits

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
debian debianbookwormfixed1:2.39.5-0+deb12u3
debian debianbullseyefixed1:2.30.2-1+deb11u5
debian debianforkyfixed1:2.50.1-0.1
debian debiansidfixed1:2.50.1-0.1
debian debiantrixiefixed1:2.47.3-0+deb13u1
suse slesaffected
rockylinux rocky9fixed

References

Verify integrity in audit chain (admin only). AS-IS.