When a user clones an untrusted repository and runs Gitk without additional command arguments, any writable file can be created and truncated. The option "Support per-file encoding" must have been enabled. The operation "Show origin of this line" is affected as well, regardless of the option being enabled or not.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:11462 https://access.redhat.com/errata/RHSA-2025:11462
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:11533 https://access.redhat.com/errata/RHSA-2025:11533
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:11534 https://access.redhat.com/errata/RHSA-2025:11534
This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2025:13276 https://access.redhat.com/errata/RHSA-2025:13276