Red Hat Product Errata RHSA-2026:67319 - Security Advisory Issued: 2026-09-14 Updated: 2026-09-14 RHSA-2026:67319 - Security Advisory Overview Updated Packages Synopsis Important: git-lfs security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for git-lfs is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) golang.org/x/net/idna: golang: net/ http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building BZ - 2467822 - CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing BZ - 2515815 - CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal BZ - 2515820 - CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution BZ - 2515839 - CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages BZ - 2515840 - CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVEs CVE-2025-68121 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-33811 CVE-2026-33818 CVE-2026-39821 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 x86_64 git-lfs-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 6a5d04468d3e3d07d2c9e3eaa096e813c2206005b9ef2cd1b5cb54c115bd3219 git-lfs-debuginfo-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 396a90beb6a18c6db7f5c0a402c4b7f1c373539f83ab590d63a7abeaef770c5b git-lfs-debugsource-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 2ebea025358f7a66c9a6e7ca8957f7ab64be4712e1b8d24bb762381928c86369 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 ppc64le git-lfs-3.2.0-2.el9_2.10.ppc64le.rpm SHA-256: f5b1e02bf7df7060b15042d3e73da4143b143ba5dad01adfb7705a1a2aef55c3 git-lfs-debuginfo-3.2.0-2.el9_2.10.ppc64le.rpm SHA-256: 811eafb2393d358dcec0c6a528ea9b8d0565822b4f7f5c0a589f58017aa2244f git-lfs-debugsource-3.2.0-2.el9_2.10.ppc64le.rpm SHA-256: d96c73cae284bab40c3794f54cc75e70f25ca763079db106439188bb2b90a545 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 x86_64 git-lfs-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 6a5d04468d3e3d07d2c9e3eaa096e813c2206005b9ef2cd1b5cb54c115bd3219 git-lfs-debuginfo-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 396a90beb6a18c6db7f5c0a402c4b7f1c373539f83ab590d63a7abeaef770c5b git-lfs-debugsource-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 2ebea025358f7a66c9a6e7ca8957f7ab64be4712e1b8d24bb762381928c86369 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 aarch64 git-lfs-3.2.0-2.el9_2.10.aarch64.rpm SHA-256: bbebe12bb8b1b7d18e4d4779b5dcb32da6b281bd6f2f096c8c4a263bc31b9d14 git-lfs-debuginfo-3.2.0-2.el9_2.10.aarch64.rpm SHA-256: 797104fbc4e2f9997bd5177b09d5fe5ed9d25894718ca2084c6c9d0733ccf22c git-lfs-debugsource-3.2.0-2.el9_2.10.aarch64.rpm SHA-256: e2e9c883a7e6411ece5f75b21a64ac48866b11f4850f9d599a996aa486bf9510 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 s390x git-lfs-3.2.0-2.el9_2.10.s390x.rpm SHA-256: 63896c697c741c39166ef2e17e2b8487122df759db1b7684275e050a24c2faa9 git-lfs-debuginfo-3.2.0-2.el9_2.10.s390x.rpm SHA-256: 437f9838594402e749d97e70c4061185e8ff14762491789ec132bcc92d1a12f2 git-lfs-debugsource-3.2.0-2.el9_2.10.s390x.rpm SHA-256: 5b7ab4283f365066d862331fe3e10101da4579515bb94229df724e74c501784f Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 x86_64 git-lfs-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 6a5d04468d3e3d07d2c9e3eaa096e813c2206005b9ef2cd1b5cb54c115bd3219 git-lfs-debuginfo-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 396a90beb6a18c6db7f5c0a402c4b7f1c373539f83ab590d63a7abeaef770c5b git-lfs-debugsource-3.2.0-2.el9_2.10.x86_64.rpm SHA-256: 2ebea025358f7a66c9a6e7ca8957f7ab64be4712e1b8d24bb762381928c86369 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 aarch64 git-lfs-3.2.0-2.el9_2.10.aarch64.rpm SHA-256: bbebe12bb8b1b7d18e4d4779b5dcb32da6b281bd6f2f096c8c4a263bc31b9d14 git-lfs-debuginfo-3.2.0-2.el9_2.10.aarch64.rpm SHA-256: 797104fbc4e2f9997bd5177b09d5fe5ed9d25894718ca2084c6c9d0733ccf22c git-lfs-debugsource-3.2.0-2.el9_2.10.aarch64.rpm SHA-256: e2e9c883a7e6411ece5f75b21a64ac48866b11f4850f9d599a996aa486bf9510 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 ppc64le git-lfs-3.2.0-2.el9_2.10.ppc64le.rpm SHA-256: f5b1e02bf7df7060b15042d3e73da4143b143ba5dad01adfb7705a1a2aef55c3 git-lfs-debuginfo-3.2.0-2.el9_2.10.ppc64le.rpm SHA-256: 811eafb2393d358dcec0c6a528ea9b8d0565822b4f7f5c0a589f58017aa2244f git-lfs-debugsource-3.2.0-2.el9_2.10.ppc64le.rpm SHA-256: d96c73cae284bab40c3794f54cc75e70f25ca763079db106439188bb2b90a545 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 SRPM git-lfs-3.2.0-2.el9_2.10.src.rpm SHA-256: 9eb7ae2a071dd45bbfc6517ee27ab70e9391e15e66e9055af95a9fc8e5ac3886 s390x git-lfs-3.2.0-2.el9_2.10.s390x.rpm SHA-256: 63896c697c741c39166ef2e17e2b8487122df759db1b7684275e050a24c2faa9 git-lfs-debuginfo-3.2.0-2.el9_2.10.s390x.rpm SHA-256: 437f9838594402e749d97e70c4061185e8ff14762491789ec132bcc92d1a12f2 git-lfs-debugsource-3.2.0-2.el9_2.10.s390x.rpm SHA-256: 5b7ab4283f365066d862331fe3e10101da4579515bb94229df724e74c501784f The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This Red Hat security update addresses multiple vulnerabilities in git-lfs, primarily stemming from its underlying Go runtime, including a critical TLS certificate validation bypass (CVE-2025-68121, CVSS 10.0) and several high-severity denial-of-service flaws in crypto, net, and encoding packages. The affected git-lfs packages are those shipped with specific Red Hat Enterprise Linux 9.2 update streams. The advisory provides a link to Red Hat's solution article for applying the patched update.