Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  Critical Git security vulnerability (CVE-2025-48384) requires git 2.43.7 or higher

    Posted Mon September 08, 2025 12:25 PM

    Hi,

    Critical Git security vulnerability (CVE-2025-48384) requires git 2.43.7 or higher. At the moment the AIX Open Source repository has 2.41.

    Are there updates planned to 2.51 (or at least >= 2.43.7) to provide a correction for CVE-2025-48384 ?

    I spent a bit of time trying to compile the tar ball but didn't get very far. What would be the approach there ?

    Thanks

    Heinz



    ------------------------------
    Heinz Sporri
    ------------------------------

    #AIXOpenSource


  • 2.  RE: Critical Git security vulnerability (CVE-2025-48384) requires git 2.43.7 or higher

    Posted Mon September 08, 2025 01:23 PM

    Thanks for notifying the vulnerability in git package.

    It is already in our planned update list and we will upload it to the toolbox mostly in a week or two.



    ------------------------------
    SANGAMESH
    ------------------------------



  • 3.  RE: Critical Git security vulnerability (CVE-2025-48384) requires git 2.43.7 or higher

    Posted Wed September 24, 2025 03:16 AM

    Hi Sangamesh,

    Any update on release of patched git version please. I checked at the OSS today and its still 2.41. Thanks.

    Regards,

    Manish Anand



    ------------------------------
    Manish Anand
    ------------------------------



  • 4.  RE: Critical Git security vulnerability (CVE-2025-48384) requires git 2.43.7 or higher

    Posted 27 days ago
    Edited by Heinz Sporri 27 days ago

    Hi Sangamesh,

    Do you have an update on the release of a patched git version please. I checked the OSS today and it's still 2.41.

    Can we be of assistance with the creation of git 2.51 for example ?

    Thanks & regards

    Heinz



    ------------------------------
    Heinz Sporri
    ------------------------------



  • 5.  RE: Critical Git security vulnerability (CVE-2025-48384) requires git 2.43.7 or higher

    Posted 27 days ago

    Hi Heinz Sporri,

    git version 2.51.2 was already uploaded to toolbox. please do a "dnf clean all" and "dnf update git"




    ------------------------------
    Lakshmi Surekha Kovvuri
    ------------------------------



  • 6.  RE: Critical Git security vulnerability (CVE-2025-48384) requires git 2.43.7 or higher

    Posted 27 days ago

    Thanks, "dnf update git" worked.



    ------------------------------
    Heinz Sporri
    ------------------------------