已关闭
fix(cve): 修复 CVE-2026-32280 在 git-lfs 中的漏洞 #26
zwjsec创建于 4月20日关闭于 23 天前
fix(cve): 修复 CVE-2026-32280 在 git-lfs 中的漏洞 #26
已关闭
共 1 个文件变更+5-2
| @@ -3,7 +3,7 @@ | |||
| 3 | 3 | ||
| 4 | Name: git-lfs | 4 | Name: git-lfs |
| 5 | Version: 3.7.1 | 5 | Version: 3.7.1 |
| 6 | -Release: 1 | 6 | +Release: 2 |
| 7 | Summary: Git extension for versioning large files | 7 | Summary: Git extension for versioning large files |
| 8 | 8 | ||
| 9 | License: MIT and BSD and Apache-2.0 and MPL-2.0 | 9 | License: MIT and BSD and Apache-2.0 and MPL-2.0 |
| @@ -19,7 +19,7 @@ BuildRequires: perl-Test-Harness | |||
| 19 | # Tests require full git suite, but not generally needed. | 19 | # Tests require full git suite, but not generally needed. |
| 20 | BuildRequires: git >= 1.8.5 | 20 | BuildRequires: git >= 1.8.5 |
| 21 | %endif | 21 | %endif |
| 22 | -BuildRequires: golang >= 1.23.0 | 22 | +BuildRequires: golang >= 1.25.9 |
| 23 | BuildRequires: tar, which | 23 | BuildRequires: tar, which |
| 24 | 24 | ||
| 25 | Requires: git-core >= 1.8.5 | 25 | Requires: git-core >= 1.8.5 |
| @@ -56,6 +56,9 @@ install -Dpm0755 src/github.com/git-lfs/git-lfs/bin/git-lfs %{buildroot}%{_bindi | |||
| 56 | 56 | ||
| 57 | 57 | ||
| 58 | %changelog | 58 | %changelog |
| 59 | +* Mon Apr 20 2026 zwjsec <zhaiwenjiesec@163.com> - 3.7.1-2 | ||
| 60 | +- fix CVE-2026-32280: Upgrade golang BuildRequires to fix crypto/x509 DoS vulnerability | ||
| 61 | + | ||
| 59 | * Sun Oct 19 2025 Funda Wang <fundawang@yeah.net> - 3.7.1-1 | 62 | * Sun Oct 19 2025 Funda Wang <fundawang@yeah.net> - 3.7.1-1 |
| 60 | - update to 3.7.1 | 63 | - update to 3.7.1 |
| 61 | 64 | ||