- What: Security update for Git LFS in Red Hat Enterprise Linux 9.6
- Impact: Systems using Git LFS may be vulnerable to denial of service attacks
Red Hat Product Errata RHSA-2026:67287 - Security Advisory Issued: 2026-09-14 Updated: 2026-09-14 RHSA-2026:67287 - Security Advisory Overview Updated Packages Synopsis Important: git-lfs security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for git-lfs is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) golang.org/x/net/idna: golang: net/ http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2515815 - CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal BZ - 2515820 - CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution BZ - 2515839 - CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVEs CVE-2026-32281 CVE-2026-33811 CVE-2026-33818 CVE-2026-39821 CVE-2026-56860 CVE-2026-56862 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c x86_64 git-lfs-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: d7b8b12c5e81bb75c7c352053f6bcf56b7a06dbab6ab7d09d74841f6e12bdcee git-lfs-debuginfo-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 008c12bb777b7c4a16d942cdc750f456beeac1b253f41ae40cd71970636d2059 git-lfs-debugsource-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 446aa0dbf1c3a04c0ce11bc422fd93282762defed65e29b8c884e736ba2ff21e Red Hat Enterprise Linux Server - AUS 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c x86_64 git-lfs-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: d7b8b12c5e81bb75c7c352053f6bcf56b7a06dbab6ab7d09d74841f6e12bdcee git-lfs-debuginfo-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 008c12bb777b7c4a16d942cdc750f456beeac1b253f41ae40cd71970636d2059 git-lfs-debugsource-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 446aa0dbf1c3a04c0ce11bc422fd93282762defed65e29b8c884e736ba2ff21e Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c s390x git-lfs-3.6.1-2.el9_6.7.s390x.rpm SHA-256: 115d5410e0b2bc0f87c269a9243c0b891d05fc2fd2a65499c1ddcc6576b8f25d git-lfs-debuginfo-3.6.1-2.el9_6.7.s390x.rpm SHA-256: 609ddca5b191251d2dafff2d6b28a30c441c79b0c03cad3f521958a7d3d42ad7 git-lfs-debugsource-3.6.1-2.el9_6.7.s390x.rpm SHA-256: 7dcb3ebe7244d505bec1e9aa773cb097dbc8455fa068ae8ec44f9da6dfbfc7aa Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c ppc64le git-lfs-3.6.1-2.el9_6.7.ppc64le.rpm SHA-256: c5d349f9838bf6a1075b67826cf14ce0e183b25179f0aaa7253c834bb807de74 git-lfs-debuginfo-3.6.1-2.el9_6.7.ppc64le.rpm SHA-256: 74e8b9284d737c1b0612655f5e5809adf154b0c9a3abd3e367e810ed446eb012 git-lfs-debugsource-3.6.1-2.el9_6.7.ppc64le.rpm SHA-256: cf92e461052608c595b8812d60f4d82b8bfd8c7bcb1540c918d5e2d59550dc43 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c aarch64 git-lfs-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: 88380de7372c47585756dd119c6fed0a50f29b5be2aba16c8943462217b567df git-lfs-debuginfo-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: bfa6df4a781e813ced0c2ec48ab502e10d0c345ba73ec1070a766d5ff164643d git-lfs-debugsource-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: 89cd68bf62dd71a8dc4f74dfd10eab86b780932848c969ca74b8a75d9f023112 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c ppc64le git-lfs-3.6.1-2.el9_6.7.ppc64le.rpm SHA-256: c5d349f9838bf6a1075b67826cf14ce0e183b25179f0aaa7253c834bb807de74 git-lfs-debuginfo-3.6.1-2.el9_6.7.ppc64le.rpm SHA-256: 74e8b9284d737c1b0612655f5e5809adf154b0c9a3abd3e367e810ed446eb012 git-lfs-debugsource-3.6.1-2.el9_6.7.ppc64le.rpm SHA-256: cf92e461052608c595b8812d60f4d82b8bfd8c7bcb1540c918d5e2d59550dc43 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c x86_64 git-lfs-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: d7b8b12c5e81bb75c7c352053f6bcf56b7a06dbab6ab7d09d74841f6e12bdcee git-lfs-debuginfo-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 008c12bb777b7c4a16d942cdc750f456beeac1b253f41ae40cd71970636d2059 git-lfs-debugsource-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 446aa0dbf1c3a04c0ce11bc422fd93282762defed65e29b8c884e736ba2ff21e Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c aarch64 git-lfs-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: 88380de7372c47585756dd119c6fed0a50f29b5be2aba16c8943462217b567df git-lfs-debuginfo-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: bfa6df4a781e813ced0c2ec48ab502e10d0c345ba73ec1070a766d5ff164643d git-lfs-debugsource-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: 89cd68bf62dd71a8dc4f74dfd10eab86b780932848c969ca74b8a75d9f023112 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c s390x git-lfs-3.6.1-2.el9_6.7.s390x.rpm SHA-256: 115d5410e0b2bc0f87c269a9243c0b891d05fc2fd2a65499c1ddcc6576b8f25d git-lfs-debuginfo-3.6.1-2.el9_6.7.s390x.rpm SHA-256: 609ddca5b191251d2dafff2d6b28a30c441c79b0c03cad3f521958a7d3d42ad7 git-lfs-debugsource-3.6.1-2.el9_6.7.s390x.rpm SHA-256: 7dcb3ebe7244d505bec1e9aa773cb097dbc8455fa068ae8ec44f9da6dfbfc7aa Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c x86_64 git-lfs-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: d7b8b12c5e81bb75c7c352053f6bcf56b7a06dbab6ab7d09d74841f6e12bdcee git-lfs-debuginfo-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 008c12bb777b7c4a16d942cdc750f456beeac1b253f41ae40cd71970636d2059 git-lfs-debugsource-3.6.1-2.el9_6.7.x86_64.rpm SHA-256: 446aa0dbf1c3a04c0ce11bc422fd93282762defed65e29b8c884e736ba2ff21e Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 SRPM git-lfs-3.6.1-2.el9_6.7.src.rpm SHA-256: ac7cdda53ab8140db57fe1483176a9d91a7bfc8fd2b1180dd62be36c50e8035c aarch64 git-lfs-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: 88380de7372c47585756dd119c6fed0a50f29b5be2aba16c8943462217b567df git-lfs-debuginfo-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: bfa6df4a781e813ced0c2ec48ab502e10d0c345ba73ec1070a766d5ff164643d git-lfs-debugsource-3.6.1-2.el9_6.7.aarch64.rpm SHA-256: 89cd68bf62dd71a8dc4f74dfd10eab86b780932848c969ca74b8a75d9f023112 Red Hat Enterprise Linux for Power, little endian - Extended L