{"id":"openSUSE-SU-2026:21558-1","summary":"Security update for gitoxide","details":"This update for gitoxide fixes the following issues:\n\nChanges in gitoxide:\n\n- Update to 0.56.0:\n  * Fixes CVE-2026-40034 (boo#1266434): the CommandForbiddenInModules\n    trust check could be bypassed in gix_submodule::File::update(),\n    which allowed arbitrary command execution from a crafted\n    .gitmodules file\n  * Fixes a submodule name validation bypass that allowed traversal\n    out of .git/modules and disclosure of credentials\n  * Fixes symlinked .gitmodules files being followed and parsed from\n    outside the repository\n  * Fixes several denial-of-service vectors in gix-pack: unchecked\n    indexing panics and uncapped allocations from crafted pack data\n  * Fixes HTTP credentials being leaked to the redirected host by the\n    curl transport backend\n  * Add the gix config show, gix config list, gix config fmt,\n    gix free remote refs, gix free trust, gix dirwalk and gix tix\n    subcommands\n  * Add a gix status --untracked flag and gix merge tree --message\n    for creating commits\n  * gix exclude query is now index-aware and no longer reports ignore\n    matches for tracked files, matching git check-ignore\n  * Preserve all configured remote URLs rather than only the last one\n  * Fix fetching and cloning with tag refspecs in shallow clones,\n    relative worktree linking files and loose ref path-prefix\n    collisions\n  * Update the crates to the Rust 2024 edition\n- Refresh the vendored dependencies. Recording the state of the\n  remaining open CVE bugs against this version, none of which it is\n  affected by:\n  * CVE-2026-25541 (boo#1274525): the vendored bytes is now 1.12.1,\n    above the 1.11.1 fix\n  * CVE-2025-22620 (boo#1236139): gix-worktree-state is 0.33.0, far\n    above the 0.17.0 that fixed the world-writable checkout of\n    executable files\n\n- update to 0.50.0:\n  see https://github.com/GitoxideLabs/gitoxide/compare/v0.42.0...v0.50.0\n\n- update to 0.42.0:\n  * add first 'debug' version of gix diff file\n  * use revspecs for revision and path\n  * CVE-2025-31130: use collision-detecting SHA-1 hash boo#1240872\n\n- Update to version 0.41.0:\n  * add gix blame -L start,end\n  * add gix env to print paths relevant to the Git installation.\n  * Document the remaining subcommands\n  * Add support for statistics and additional performance\n    information.\n  * add gix blame to the CLI. That way it's possible to see the\n    blame result of any file in the repository.\n\n- Updates from version 0.40.0:\n  * add first 'debug' version of gix log. It's primarily meant to\n    better understand gix blame.\n  * add --tree-favor to gix merge tree|commit. With it one can\n    decide which side to favor in case of irreconcilable\n    tree-conflicts.\n  * CVE-2025-22620: gix-worktree-state specifies 0777 permissions\n    when checking out executable files (boo#1236139)\n\n- Update to version 0.39.0:\n  New Features\n  * add gix merge commit --debug\n  * add gix merge commits\n  * add gix merge tree to merge trees similarly to git merge-tree.\n\n- Update to version 0.38.0:\n  New Features\n  * support for listing worktrees with gix worktree list\n  * add first 'debug' version of gix diff tree.\n  * add new gix cat command.\n  * add gix merge-file with similar features as git merge-file\n  * gix merge-base for the CLI\n  Bug Fixes\n  * Adjust gix clean warning and help for worktree fix\n  * Clarify -r/--repositories and --skip-hidden-repositories\n  Other\n  * switch from time to jiff\n  * Unify style in config support info\n","modified":"2026-08-12T18:23:52.337160580Z","published":"2026-08-10T13:10:07Z","related":["CVE-2024-32650","CVE-2025-22620","CVE-2025-31130","CVE-2026-25541","CVE-2026-40034"],"upstream":["CVE-2024-32650","CVE-2025-22620","CVE-2025-31130","CVE-2026-25541","CVE-2026-40034"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1223249"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236139"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240872"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266434"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-32650"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31130"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40034"}],"affected":[{"package":{"name":"gitoxide","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gitoxide&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.56.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"gitoxide":"0.56.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21558-1.json"}}],"schema_version":"1.9.0"}