PT-2025-28649 · Git +4 · Git +4
Dgl
·
Published
2025-07-08
·
Updated
2025-07-27
·
CVE-2025-48386
7.8
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Git versions prior to 2.43.7
Git versions prior to 2.44.4
Git versions prior to 2.45.4
Git versions prior to 2.46.4
Git versions prior to 2.47.3
Git versions prior to 2.48.2
Git versions prior to 2.49.1
Git versions prior to 2.50.1
Description:
The wincred credential helper in Git does not properly bounds check the available space remaining in a static buffer before appending to it with wcsncat(), leading to potential buffer overflows.
Recommendations:
For versions prior to 2.43.7, update to version 2.43.7 or later.
For versions prior to 2.44.4, update to version 2.44.4 or later.
For versions prior to 2.45.4, update to version 2.45.4 or later.
For versions prior to 2.46.4, update to version 2.46.4 or later.
For versions prior to 2.47.3, update to version 2.47.3 or later.
For versions prior to 2.48.2, update to version 2.48.2 or later.
For versions prior to 2.49.1, update to version 2.49.1 or later.
For versions prior to 2.50.1, update to version 2.50.1 or later.
Fix
Buffer Overflow
Weakness Enumeration
Related Identifiers
Affected Products
References · 55
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48386 · Security Note
- https://osv.dev/vulnerability/BELL-CVE-2025-48386 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-09361 · Security Note
- https://ubuntu.com/security/notices/USN-7626-3 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-46835 · Vendor Advisory
- https://ubuntu.com/security/notices/USN-7626-1 · Vendor Advisory
- https://osv.dev/vulnerability/USN-7626-3 · Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2025-48386 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-48385 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48385 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-48386 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46835 · Security Note
- https://bdu.fstec.ru/vul/2025-09363 · Security Note
- https://ubuntu.com/security/CVE-2025-27614 · Vendor Advisory
- https://cve.org/CVERecord?id=CVE-2025-48386 · Security Note