🛡️ SUSE-SU-2025:20049-1 — git (CVE-2024-32002 +6 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for git

This update for git fixes the following issues:

git was updated to 2.45.1:

  • CVE-2024-32002: recursive clones on case-insensitive

filesystems that support symbolic links are susceptible to case

confusion (bsc#1224168)

  • CVE-2024-32004: arbitrary code execution during local clones

(bsc#1224170)

  • CVE-2024-32020: file overwriting vulnerability during local

clones (bsc#1224171)

  • CVE-2024-32021: git may create hardlinks to arbitrary user-

readable files (bsc#1224172)

  • CVE-2024-32465: arbitrary code execution during clone operations

(bsc#1224173)

Update to 2.45.0:

  • Improved efficiency managing repositories with many references

("git init --ref-format=reftable")

  • "git checkout -p" and friends learned that that "@" is a

synonym for "HEAD"

  • cli improvements handling refs
  • Expanded a number of commands and options, UI improvements
  • status.showUntrackedFiles now accepts "true"
  • git-cherry-pick(1) now automatically drops redundant commits

with new --empty option

  • The userdiff patterns for C# has been updated.

Update to 2.44.0:

  • "git checkout -B <branch>" now longer allows switching to a

branch that is in use on another worktree. The users need to

use "--ignore-other-worktrees" option.

  • Faster server-side rebases with git replay
  • Faster pack generation with multi-pack reuse
  • rebase auto-squashing now works in non-interactive mode
  • pathspec now understands attr, e.g. ':(attr:~binary) for

selecting non-binaries, or builtin_objectmode for selecting

items by file mode or other properties

  • Many other cli UI and internal improvements and extensions
  • Do not replace apparmor configuration, fixes bsc#1216545

Update to 2.43.2:

  • https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.2.txt
  • Update to a new feature recently added, "git show-ref --exists".
  • Rename detection logic ignored the final line of a file if it

is an incomplete line.

  • "git diff --no-rename A B" did not disable rename detection but

did not trigger an error from the command line parser.

  • "git diff --no-index file1 file2" segfaulted while invoking the

external diff driver, which has been corrected.

  • A failed "git tag -s" did not necessarily result in an error

depending on the crypto backend, which has been corrected.

  • "git stash" sometimes was silent even when it failed due to

unwritable index file, which has been corrected.

  • Recent conversion to allow more than 0/1 in GIT_FLUSH broke the

mechanism by flipping what yes/no means by mistake, which has

been corrected.

Update to 2.43.1:

  • https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.1.txt
  • gitweb AppArmor profile: allow reading etc/gitweb-common.conf

(bsc#1218664)

  • git moved to /usr/libexec/git/git, update AppArmor profile

accordingly (bsc#1218588)

Update to 2.43.0:

  • The "--rfc" option of "git format-patch" used to be a valid way to

override an earlier "--subject-prefix=<something>" on the command

line and replace it with "[RFC PATCH]", but from this release, it

merely prefixes the string "RFC " in front of the given subject

prefix. If you are negatively affected by this change, please use

"--subject-prefix=PATCH --rfc" as a replacement.

  • In Git 2.42, "git rev-list --stdin" learned to take non-revisions

(like "--not") from the standard input, but the way such a "--not" was

handled was quite confusing, which has been rethought. The updated

rule is that "--not" given from the command line only affects revs

given from the command line that comes but not revs read from the

standard input, and "--not" read from the standard input affects

revs given from the standard input and not revs given from the

command line.

  • A message written in olden time prevented a branch from getting

checked out, saying it is already checked out elsewhere. But these

days, we treat a branch that is being bisected or rebased just like

a branch that is checked out and protect it from getting modified

with the same codepath. The message has been rephrased to say that

the branch is "in use" to avoid confusion.

  • Hourly and other schedules of "git maintenance" jobs are randomly

distributed now.

  • "git cmd -h" learned to signal which options can be negated by

listing such options like "--[no-]opt".

  • The way authentication related data other than passwords (e.g.,

oauth token and password expiration data) are stored in libsecret

keyrings has been rethought.

  • Update the libsecret and wincred credential helpers to correctly

match which credential to erase; they erased the wrong entry in

some cases.

  • Git GUI updates.
  • "git format-patch" learned a new "--description-file" option that

lets cover letter description to be fed; this can be used on

detached HEAD where there is no branch description available, and

also can ov

Affected software

SUSE-SU-2025:20049-1 is recorded against 1 package.

  • git (fixed in 2.45.1-1.1)

Timeline and source

Published on 3 February 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-02-03
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
git 2.45.1-1.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20049-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20049-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025