[CLSA-2026:1773138498] git-lfs: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-03-10 10:28:22 UTC
Description:
- Rebuild with Go 1.25.7 to fix Go standard library CVEs - CVE-2025-68121: fix TLS session resumption accepting revoked/expired certificates - CVE-2025-61726: fix DoS via excessive memory consumption in net/url query parsing
Updated packages:
  • git-lfs-3.6.1-2.el9_6.tuxcare.els2.x86_64.rpm
    sha:c355d017345ab4a8e2b8dad8f6709cdafb6c5e0a1d91c26b6056573173f5f038
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.