RE: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status
- From
- Person, Tim <tim.person@personent.com>
- Date
- Jun 27, 2026, 21:17 UTC
- Message-ID
- <SN4P221MB071311FDE610296A5059E8F994EA2@SN4P221MB0713.NAMP221.PROD.OUTLOOK.COM>
- In-Reply-To
- <20260627210718.zl0eH_Sc@teonanacatl.net>
Todd,
Thank you for the reply, the explanation, and the information about who to contact.
Thanks,
Tim
-----Original Message----- From: Todd Zullinger <tmz@pobox.com> Sent: Saturday, June 27, 2026 2:07 PM To: Person, Tim <Tim.Person@personent.com> Cc: git@vger.kernel.org Subject: Re: Security Vulnerability in Git 2.54.0/OpenSSL 3.5.6 Status
[You don't often get email from tmz@pobox.com. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
[CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe.]
Hi,
Person, Tim wrote:
Show 8 quoted lines
> I am writing to determine when Git plans to release an update > installer to patch the security vulnerability in Git 2.54.0 because of > the included OpenSSL executable. > This vulnerability is rated "Critical" in the CVE > (https://www/ > .cve.org%2FCVERecord%3Fid%3DCVE-2026-34182&data=05%7C02%7CTim.Person%4 > 0personentcloud.mail.onmicrosoft.com%7C350b58458bd84a5312f308ded490243 > 8%7Ce2de18dc8323462e8c47561025ebc66c%7C0%7C0%7C639181913006654964%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C40000%7C%7C%7C&sdata=caMSGrA%2FfpxkKs2o%2Bg1dE9JuEQQlOK3IBt8BzbZ%2F7GM%3D&reserved=0). An updated version of the OpenSSL.exe fixing this problem has been available since 06/12/2026. I am just wondering if/when you plan to address this major security issue.
The Git project does not distribute any binaries. You likely want to direct this to the Git for Windows project¹.
That said, it's not even clear to me that the CVE you reference affects git's usage of OpenSSL.
From a little skimming, the issue affects use of CMS (which is something like the successor to S/MIME, as far as I can tell).
The only place where git gets close to that area is if you configure it to use x509 as gpg.program. And then git uses gpgsm, which is not affected by the CVE in OpenSSL.
¹ https://gitforwindows.org/
-- Todd