Input validation error in Git - CVE-2025-48385

 

Input validation error in Git - CVE-2025-48385

Published: July 9, 2025


Vulnerability identifier: #VU112638
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-48385
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected client.

The vulnerability exists due to insufficient validation of bundle-uri parameter when cloning a repository. A remote attacker can trick the victim into cloning a specially crafted repository, perform a protocol injection attack and write code to arbitrary locations on the system, leading to remote code execution. 


Affected software

Git
Red Hat OpenShift Container Platform
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Basesystem Module
Development Tools Module
Python 3 Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
obs-scm-bridge
git (Ubuntu package)
git (Red Hat package)
git
git-core
git-daemon
git-debuginfo
git-debugsource
git-email
git-gui
git-help
git-svn
git-web
gitk
perl-Git
perl-Git-SVN
gitweb
git-instaweb
git-credential-libsecret
git-subtree
git-all
git-core-doc
git-doc
git-arch
git-daemon-debuginfo
git-cvs
git-core-debuginfo
git-credential-libsecret-debuginfo
git-p4
dev-vcs/git
git-lfs
python311-PyYAML-debuginfo
python311-PyYAML
python-PyYAML-debugsource
Visual Studio
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
ExtremeCloud IQ Site Engine

How to mitigate CVE-2025-48385

Install updates from vendor's website.

Git - addressed in versions 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, 2.50.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
Visual Studio - addressed in versions 16.11.49 16.11.49, 17.8.23 17.8.23, 17.10.17 17.10.17, 17.12.10 17.12.10
obs-scm-bridge - update to 0.7.4-150600.14.4.1
Ansible Automation Platform - update to 2.5
git (Ubuntu package) - addressed in versions 1:2.7.4-0ubuntu1.10+esm9, 1:2.7.4-0ubuntu1.10+esm10, 1:2.7.4-0ubuntu1.10+esm11, 1:2.17.1-1ubuntu0.18+esm2, 1:2.17.1-1ubuntu0.18+esm3, 1:2.17.1-1ubuntu0.18+esm4, 1:2.25.1-1ubuntu3.14+esm1, 1:2.25.1-1ubuntu3.14+esm2, 1:2.25.1-1ubuntu3.14+esm3, 1:2.34.1-1ubuntu1.13, 1:2.34.1-1ubuntu1.14, 1:2.34.1-1ubuntu1.15, 1:2.43.0-1ubuntu7.3, 1:2.45.2-1ubuntu1.2, 1:2.48.1-0ubuntu1.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.4
git (Red Hat package) - addressed in versions 2.39.5-1.el8_8.2, 2.39.5-1.el9_2.2, 2.43.5-1.el9_4.2, 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0
git - update to 2.43.0-9
git-core - update to 2.43.0-9
git-daemon - update to 2.43.0-9
git-debuginfo - update to 2.43.0-9
git-debugsource - update to 2.43.0-9
git-email - update to 2.43.0-9
git-gui - update to 2.43.0-9
git-help - update to 2.43.0-9
git-svn - update to 2.43.0-9
git-web - update to 2.43.0-9
gitk - update to 2.43.0-9
perl-Git - update to 2.43.0-9
perl-Git-SVN - update to 2.43.0-9
git - addressed in versions 2.43.7-1.0.1, 2.47.3-1
perl-Git-SVN - addressed in versions 2.43.7-1.0.1, 2.47.3-1
perl-Git - addressed in versions 2.43.7-1.0.1, 2.47.3-1
gitweb - addressed in versions 2.43.7-1.0.1, 2.47.3-1
gitk - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-svn - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-instaweb - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-gui - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-core - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-credential-libsecret - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-daemon - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-subtree - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-all - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-core-doc - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-email - addressed in versions 2.43.7-1.0.1, 2.47.3-1
git-credential-libsecret - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-core - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-doc - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
perl-Git - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-email - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-arch - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-daemon-debuginfo - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-daemon - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-cvs - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-gui - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
gitk - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-web - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-svn - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-core-debuginfo - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-debugsource - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-debuginfo - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-credential-libsecret-debuginfo - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-p4 - addressed in versions 2.43.7-150300.10.51.1, 2.51.0-150600.3.12.1
git-p4 - update to 2.47.3-1
dev-vcs/git - update to 2.49.1
git - addressed in versions 2.50.1-1.fc41, 2.50.1-1.fc42
git-lfs - update to 3.7.0-150600.13.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.13.60, 4.14.54, 4.14.56, 4.15.56, 4.15.57, 4.16.46, 4.16.47, 4.17.37, 4.17.38, 4.18.22, 4.19.6, 4.19.7, 4.19.9
python311-PyYAML-debuginfo - update to 6.0.2-150600.10.3.1
python311-PyYAML - update to 6.0.2-150600.10.3.1
python-PyYAML-debugsource - update to 6.0.2-150600.10.3.1
ExtremeCloud IQ Site Engine - update to 25.8.10

External References

Related Security Bulletins