git/list[1] front-page[2] threads[3] people[4] search[5] about
 

question about affected version of CVE-2025-48385

From
JWJinfeng Wang <jinfeng.wang.cn@windriver.com>
Date
Jan 7, 2026, 05:36 UTC
Message-ID
<44c4e575-bf5c-45a4-8035-ad4007e95fe3@windriver.com>
Hi all,
For this CVE https://nvd.nist.gov/vuln/detail/CVE-2025-48385,

Affected vesion listed in https://github.com/git/git/security/advisories/GHSA-m98c-vgpc-9655: Affected versions v2.50.0, v2.49.0, v2.48.0-v2.48.1, v2.47.0–v2.47.2, v2.46.0–v2.46.3, v2.45.0-v2.45.3, v2.44.0–v2.44.3, v2.43.6 and prior

But I see the fix is for bundle-uri:
git log --grep="CVE-2025-48385"
commit d2bc61fcabd6cfa582d286bed1ce20d5d7c58d52
Merge: d61cfed2c2 35cb1bb0b9
Author: Taylor Blau <me@ttaylorr.com>
Date:   Wed May 28 12:53:52 2025 -0400
     Merge branch 'ps/bundle-uri-arbitrary-writes' into maint-2.43
     This merges in the fix for CVE-2025-48385.
     * ps/bundle-uri-arbitrary-writes:
       bundle-uri: fix arbitrary file writes via parameter injection

But bundle-uri is added in v2.38.0, so the version before v2.38.0 is not affected. Is that right?

Regards,
Jinfeng
Message 1 of 1 in “question about affected version of CVE-2025-48385”
  1. Jinfeng WangJan 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.