Red Hat released multiple Important security updates for git-lfs across Red Hat Enterprise Linux 8, 9, and 10 after the package inherited several vulnerabilities from Go components. The advisories cover CVE-2026-32282, a flaw in Go's internal/syscall/unix where Root.Chmod can follow symlinks outside an intended root on Linux, as well as denial-of-service issues in crypto/tls and crypto/x509; some RHEL 8, 9, and 10 channels also include CVE-2026-25679, an incorrect IPv6 host literal parsing bug in net/url. Updated packages were issued for multiple architectures and support streams, including Extended Update Support and Extended Life Cycle variants.
According to Red Hat's bug tracking, CVE-2026-32282 stems from Linux fchmodat behavior that ignores the AT_SYMLINK_NOFOLLOW flag, creating a time-of-check to time-of-use race in which an attacker could swap a checked target for a symlink before chmod executes. Red Hat rated that underlying Go issue Medium severity, but bundled git-lfs fixes were published under advisories including RHSA-2026:16875, RHSA-2026:14200, RHSA-2026:19350, RHSA-2026:19133, RHSA-2026:19715, and RHSA-2026:19722, with updated builds such as git-lfs-3.4.1-10.el8_10, 3.6.1-8.el9_7.1, 3.6.1-2.el9_6.4, 3.7.1-4.el9_8, 3.6.1-2.el10_0.4, and 3.7.1-4.el10_2.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:19722 for git-lfs on Red Hat Enterprise Linux 9.6 channels, shipping version 3.6.1-2.el9_6.4. The update remediated CVE-2026-32282 together with two other Go-related vulnerabilities across several RHEL 9.6 service streams and architectures.
Red Hat published RHSA-2026:19715 for git-lfs in Red Hat Enterprise Linux 10.0 channels, providing git-lfs-3.6.1-2.el10_0.4 packages. The advisory fixed CVE-2026-32282 along with CVE-2026-32283 and CVE-2026-32280 for multiple RHEL 10.0 architectures.
Red Hat published RHSA-2026:19350 for git-lfs on Red Hat Enterprise Linux 9, shipping git-lfs-3.7.1-4.el9_8 packages. This advisory addressed CVE-2026-32282 and three other Go-derived flaws for RHEL 9.8-related product variants.
Red Hat published RHSA-2026:19133 for git-lfs on Red Hat Enterprise Linux 10, releasing git-lfs-3.7.1-4.el10_2 packages. The update fixed CVE-2026-32282 and three additional Go vulnerabilities across multiple RHEL 10 architectures and lifecycle channels.
Red Hat published RHSA-2026:16875 for git-lfs on Red Hat Enterprise Linux 8, providing updated git-lfs-3.4.1-10.el8_10 packages. The advisory remediated CVE-2026-32282 together with three other Go-related vulnerabilities across RHEL 8 and Extended Life Cycle 8.10 variants.
Red Hat published RHSA-2026:14200 for git-lfs on Red Hat Enterprise Linux 9, shipping version 3.6.1-8.el9_7.1. The advisory fixed CVE-2026-32282 along with CVE-2026-32283 and CVE-2026-32280 across multiple RHEL 9 architectures and support channels.
Red Hat recorded bug 2456336 for CVE-2026-32282, a Go Linux vulnerability in internal/syscall/unix where Root.Chmod can follow symlinks out of the intended root in a race condition scenario. The bug was classified with medium severity and medium priority.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.