Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:0673 https://access.redhat.com/errata/RHSA-2025:0673
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2025:0757 https://access.redhat.com/errata/RHSA-2025:0757
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:0758 https://access.redhat.com/errata/RHSA-2025:0758
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:0759 https://access.redhat.com/errata/RHSA-2025:0759
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2025:0762 https://access.redhat.com/errata/RHSA-2025:0762
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:0765 https://access.redhat.com/errata/RHSA-2025:0765
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2025:0825 https://access.redhat.com/errata/RHSA-2025:0825
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:0845 https://access.redhat.com/errata/RHSA-2025:0845