<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE1-SA-2025-0023</id>
    <title>An update for git is now available for HCE 1.1</title>
    <severity>Important</severity>
    <release>HCE 1.1</release>
    <issued date="2025-09-24 23:31:26"/>
    <updated date="2025-09-24 23:31:26"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-48384" id="CVE-2025-48384" title="CVE-2025-48384 Base Score: 8.0 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1. (CVE-2025-48384)
</description>
    <pkglist>
      <collection short="HCE 1.1" package="git">
        <name>HCE 1.1</name>
        <package arch="x86_64" name="git" version="1.8.3.1" release="25.0.1.hce1c">
          <filename>git-1.8.3.1-25.0.1.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="noarch" name="perl-Git" version="1.8.3.1" release="25.0.1.hce1c">
          <filename>perl-Git-1.8.3.1-25.0.1.hce1c.noarch.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
