[ANNOUNCEMENT] Security update: Git v2.35.2-1

Adam Dinwoodie adam@dinwoodie.org
Wed Apr 13 07:49:34 GMT 2022


Version 2.35.2-1 of Git has been uploaded and should be coming soon to a
mirror near you.

This is an update to the latest upstream release, and fixes security
vulnerability CVE-2022-24765:

> On multi-user machines, Git users might find themselves unexpectedly
> in a Git worktree, e.g. when another user created a repository in
> `C:\.git`, in a mounted network drive or in a scratch space. Merely
> having a Git-aware prompt that runs `git status` (or `git diff`) and
> navigating to a directory which is supposedly not a Git worktree, or
> opening such a directory in an editor or IDE such as VS Code or Atom,
> will potentially run commands defined by that other user.

This update includes the following packages:

- git
- git-cvs
- git-debuginfo
- git-email
- git-gui
- gitk
- git-p4
- git-svn

For a full list of the upstream changes in this release, please refer to the
upstream changelogs, available at:

https://git.kernel.org/cgit/git/git.git/tree/Documentation/RelNotes
https://github.com/git/git/tree/master/Documentation/RelNotes

Enjoy!


More information about the Cygwin mailing list