CODERED VTA

Red Hat Patches Bundled Go Library Flaws in Git LFS for Enterprise Linux

High
Analyst at a workstation in a dark room
Photo by Possessed Photography on Unsplash

Red Hat published security advisory RHSA-2026:72276 on 28 September 2026, delivering an updated git-lfs package for Red Hat Enterprise Linux 9.4 customers on the long-tail support streams. Git Large File Storage is the extension that swaps large binaries such as video, datasets and graphics for text pointers inside a Git repository while the real content sits on a remote server, and it is compiled from Go. The advisory closes twelve flaws inherited from the Go standard library and related Go modules, tracked as CVE-2025-68121, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-33811, CVE-2026-33818, CVE-2026-39821, CVE-2026-42504, CVE-2026-56859, CVE-2026-56860 and CVE-2026-56862. Affected builds span Red Hat Enterprise Linux Server AUS 9.4, Update Services for SAP Solutions on x86_64 and Power LE, the four-years-of-updates streams for ARM 64 and IBM Z, and the Extended Life Cycle streams for x86_64, ARM 64, Power little endian and IBM Z. The fixed package is git-lfs-3.4.1-4.el9_4.6, shipped for x86_64, ppc64le, aarch64 and s390x alongside matching debuginfo and debugsource RPMs.

Red Hat has not published exploitation details beyond the per-CVE summaries, and no proof-of-concept code is referenced in the errata, so the mechanism is described here only as far as the vendor states it. The defects sit in Go components that handle untrusted remote input: crypto/tls performs incorrect certificate validation during TLS session resumption (CVE-2025-68121) and can be driven into denial of service by repeated or indefinite TLS 1.3 KeyUpdate messages (CVE-2026-32283, CVE-2026-56862), while crypto/x509 suffers inefficient certificate chain validation and a denial of service in chain building (CVE-2026-32281, CVE-2026-32280). Parsing routines account for most of the remainder, with denial of service reachable through a long CNAME response in LookupCNAME (CVE-2026-33811), excessive recursion in encoding/asn1 Unmarshal (CVE-2026-33818), a crafted MIME header (CVE-2026-42504), XML decoding recursion depth (CVE-2026-56859) and quadratic complexity in net/url path resolution (CVE-2026-56860). Two issues fall outside the availability bucket: internal/syscall/unix allows Root.Chmod to follow symlinks out of the intended root (CVE-2026-32282), and golang.org/x/net/idna is recorded as a privilege escalation arising from incorrect Punycode label processing (CVE-2026-39821). Because Go binaries are statically linked, each of these library defects is carried inside the git-lfs executable itself rather than in a shared system library.

That static linking is the strategic point for defenders. Updating the operating system's golang or TLS components does not clean up a Go application that was already compiled, which is why a separate git-lfs errata exists at all and why every Go-derived package in an estate has to be tracked individually against the same CVE list. Git LFS typically runs where source code is handled, on developer workstations, build servers and CI runners that fetch content from remote LFS endpoints over TLS and HTTP, which is precisely the untrusted-input path these flaws sit on. The affected streams also matter: AUS, Extended Life Cycle and Update Services for SAP Solutions hosts are deliberately frozen production systems under tight change control, so they tend to accumulate patch debt and sit close to business-critical workloads. On current exploitation status, FIRST EPSS places CVE-2025-68121 at a 0.9 percent probability of exploitation in the next 30 days, CVE-2026-32283 and CVE-2026-32280 at 0.7 percent, CVE-2026-32281 at 0.4 percent and CVE-2026-32282 at 0.2 percent; no exploitation data was supplied for the remaining seven CVEs, and no confirmed in-the-wild activity or CISA KEV listing is associated with any of them.

Attack Surface

Server OS, Endpoint, File Transfer

Tactics

Impact, Privilege Escalation, Defense Evasion

Techniques

  • T1499 – Endpoint Denial of Service
  • T1068 – Exploitation for Privilege Escalation
  • T1557 – Adversary-in-the-Middle

SuperPRO's Threat Countermeasures Procedures

  1. Apply RHSA-2026:72276 by upgrading git-lfs to 3.4.1-4.el9_4.6 (plus git-lfs-debuginfo and git-lfs-debugsource where installed) on RHEL 9.4 AUS, Update Services for SAP Solutions, four-years-of-updates and Extended Life Cycle hosts, following the update procedure at https://access.redhat.com/articles/11258. With no confirmed exploitation, schedule this in the next routine maintenance window rather than as an emergency change, targeting completion within 30 days and prioritising SAP Solutions hosts that are hardest to reschedule.
  2. Enumerate exposure with 'rpm -q git-lfs' across the 9.4 estate; any build lower than 3.4.1-4.el9_4.6 is affected, and packages were shipped for x86_64, ppc64le, aarch64 and s390x, so ARM 64 and IBM Z systems must be included in the sweep, not just x86_64.
  3. Use the Red Hat Lightspeed patch analysis view linked from the errata to list systems flagged against RHSA-2026:72276, and reconcile that list against your CMDB so Extended Life Cycle hosts that are not registered for regular content still get remediated.
  4. Validate the downloaded packages before pushing them into Satellite or an internal mirror by checking the published SHA-256 values, for example d21b02329626f03654704d56e45e3b8333cef50b0794b31ad850d188814d116c for git-lfs-3.4.1-4.el9_4.6.x86_64.rpm and 94b2602d4383f88de4c35ff1df8056bb88d374fab9ce52f53b9d1f0195be87fa for the source RPM.
  5. Treat this as a statically linked Go problem, not a system library problem: updating the golang or system TLS packages does not remediate an already-compiled binary, so re-scan every other Go-derived RPM in the estate against the same CVE set (CVE-2025-68121 and CVE-2026-32280 through CVE-2026-56862) and request the corresponding errata.
  6. Constrain where unpatched Git LFS clients talk by pinning lfs.url in .lfsconfig or the repository Git config to approved internal LFS endpoints on build agents and CI runners, so crafted TLS, MIME, ASN.1 or XML responses from arbitrary remote servers cannot reach the vulnerable parsing paths.
  7. Add detection for the denial-of-service class described in the advisory: alert on repeated git-lfs process crashes, OOM kills naming git-lfs in journald or dmesg, and sustained single-core CPU saturation by git-lfs during clone or fetch operations on build servers.

Source

Code Red Cyber / VTA – coderedcyber.ai