Your message dated Tue, 01 Sep 2026 00:34:10 +0000
with message-id <[email protected]>
and subject line Bug#1144929: fixed in python-git 3.1.61-1
has caused the Debian Bug report #1144929,
regarding python-git: CVE-2026-76217 CVE-2026-76218 CVE-2026-76219
CVE-2026-76220 CVE-2026-76221 CVE-2026-76222
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144929: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144929
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-git
Version: 3.1.50-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for python-git.
CVE-2026-76217[0]:
| GitPython versions before 3.1.58 fail to validate options passed to
| git rm and git checkout commands in IndexFile.remove() and
| Head.checkout(). Attackers can supply --pathspec-from-file and
| --pathspec-file-nul parameters to read arbitrary files accessible to
| the process, with full file contents returned in
| GitCommandError.stderr.
CVE-2026-76218[1]:
| GitPython before 3.1.58 contains a remote code execution
| vulnerability in Repo.init that forwards unsafe git options without
| validation. Attackers can supply a template parameter pointing to a
| directory with malicious git hooks that execute arbitrary code when
| git operations are performed on the initialized repository.
CVE-2026-76219[2]:
| GitPython versions before 3.1.58 contain an arbitrary file overwrite
| vulnerability in IndexFile.from_tree, IndexFile.reset, and
| IndexFile.merge_tree methods that append caller-influenced treeish
| strings to git read-tree without option validation or argument
| separation. Attackers can inject the --index-output option to
| overwrite arbitrary files with a valid git-index blob, destroying
| existing file content at attacker-controlled writable paths.
CVE-2026-76220[3]:
| GitPython before 3.1.58 contains a command execution vulnerability
| in the check_unsafe_options guard that can be bypassed by combining
| a single-character kwarg with split_single_char_options=False.
| Attackers can supply a crafted kwargs dictionary to guarded methods
| like clone_from to emit a joined token parsed as --upload-pack,
| enabling arbitrary OS command execution at default
| allow_unsafe_options=False.
CVE-2026-76221[4]:
| GitPython before 3.1.58 contains a config-name injection
| vulnerability in the option-name validator that allows attackers to
| forge arbitrary git-config directives by injecting equals signs,
| hash symbols, and whitespace into option names. Attackers can inject
| malicious option names like 'sshCommand = touch /tmp/RCE #' to
| execute arbitrary commands via core.sshCommand or core.hooksPath on
| the next git operation.
CVE-2026-76222[5]:
| GitPython before 3.1.58 fails to validate submodule names from
| .gitmodules files, allowing attackers to create Git repositories at
| arbitrary filesystem paths outside the intended clone directory.
| Attackers can craft malicious repositories with traversal sequences
| in submodule names that GitPython processes during submodule
| initialization, creating attacker-controlled Git repositories at
| escaped filesystem locations.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-76217
https://www.cve.org/CVERecord?id=CVE-2026-76217
[1] https://security-tracker.debian.org/tracker/CVE-2026-76218
https://www.cve.org/CVERecord?id=CVE-2026-76218
[2] https://security-tracker.debian.org/tracker/CVE-2026-76219
https://www.cve.org/CVERecord?id=CVE-2026-76219
[3] https://security-tracker.debian.org/tracker/CVE-2026-76220
https://www.cve.org/CVERecord?id=CVE-2026-76220
[4] https://security-tracker.debian.org/tracker/CVE-2026-76221
https://www.cve.org/CVERecord?id=CVE-2026-76221
[5] https://security-tracker.debian.org/tracker/CVE-2026-76222
https://www.cve.org/CVERecord?id=CVE-2026-76222
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: python-git
Source-Version: 3.1.61-1
Done: Emmanuel Arias <[email protected]>
We believe that the bug you reported is fixed in the latest version of
python-git, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Emmanuel Arias <[email protected]> (supplier of updated python-git package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 31 Aug 2026 21:04:23 -0300
Source: python-git
Architecture: source
Version: 3.1.61-1
Distribution: unstable
Urgency: high
Maintainer: Debian Python Team <[email protected]>
Changed-By: Emmanuel Arias <[email protected]>
Closes: 1143454 1143602 1144344 1144929 1145672
Changes:
python-git (3.1.61-1) unstable; urgency=high
.
* Team upload.
* New upstream version 3.1.61.
- Fix CVE-2026-67323, CVE-2026-67324, CVE-2026-67325, CVE-2026-67322,
CVE-2026-69097, CVE-2026-73623, CVE-2026-73624, CVE-2026-73625,
CVE-2026-73622, CVE-2026-73621, CVE-2026-73619, CVE-2026-73620,
CVE-2026-76217, CVE-2026-76218, CVE-2026-76219, CVE-2026-76220,
CVE-2026-76221, CVE-2026-76222, CVE-2026-78675, CVE-2026-78676,
CVE-2026-78677, CVE-2026-78678, CVE-2026-78679 (Closes: #1143454,
#1143602, #1144344, #1144929, #1145672)
* d/tests/control: Add procps to the autopkgtest dependencies.
Checksums-Sha1:
aee695ae6710f3259917dff61402c23a6cc48ffc 2798 python-git_3.1.61-1.dsc
a0d48c24a098aa3437ea3524b3095e3d65618c67 1022655 python-git_3.1.61.orig.tar.gz
5fd8979e50dbe3ce029237490547254d02b7ef6f 7332 python-git_3.1.61-1.debian.tar.xz
7a3a8741d51ab103eadec2eaa337b7e661ab7f24 8174
python-git_3.1.61-1_amd64.buildinfo
Checksums-Sha256:
4dac291bf776a187d1f211780f6e80fe36654fe3f668e8d0177b16a6c6369bb0 2798
python-git_3.1.61-1.dsc
e919636aa7a259f9d9ece36037380b70262c7b76e6e93346be13fa0c23cda997 1022655
python-git_3.1.61.orig.tar.gz
cf75d0e27114f71cfe5f61582104f9f2a5fb904a46c1f20cff60a67ce38f1062 7332
python-git_3.1.61-1.debian.tar.xz
551a06eec67c03aeb2f08ce5812206e98e20af81f0d048db5a61913a34eadc2b 8174
python-git_3.1.61-1_amd64.buildinfo
Files:
d9edf33bd778b4cc68fbba90b8a29c14 2798 python optional python-git_3.1.61-1.dsc
4b2374b7714c18ef801dea5bccb2c5f4 1022655 python optional
python-git_3.1.61.orig.tar.gz
ed9f37cb6e1b66441d9ba96a9b2411b5 7332 python optional
python-git_3.1.61-1.debian.tar.xz
25928b55bbec50f03910085555ba12dc 8174 python optional
python-git_3.1.61-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmqWF8sSHGVhbWFudUBk
ZWJpYW4ub3JnAAoJEPqd7F3hHGPx/swQAL1PlG7fMLHGnyCEG6pQLRILniXDQ3xw
aRmH2T2JxYsnKb7JoNBhCqpzqrfUGS98gA/iN+a6ZuNBypZkOPdh/hXH/WY8O3Ma
79SurPprRe+eTAT1J6oXyR+MgwuGt/nIpnD6XQWV4gjkIXurC2pejfBtDqYOTxgj
rmlY9zJOsKFNe1CEK9HkY+JsYiu5AfBm5oUbeDZiU50bpjT8ZJXWqLexMS+hCCHA
hGmnKZEUxPYjcdxbp3li2fy7y2bWvb5Ty85fWFhcMGVDiAgTeAYYa/YSHJO3k0+0
3EK3W07rbZbBjjm8iYAIupeyboocxd6ellWPoBucK4psfybpCqUGsFii0ex1UAwj
uMdrxdbOgWfD+aC+3oRPF9IIguJ63FqV2gNs+fJGKudlTU8X4TRy8D9YcG0/+/a3
EmuZ1HUtOsy+wvd1ol6r0geOwXWleYRNpANK2czzRq8Yb0hjSnn0zw/3YfCifLTr
2gT9Was29RXiVGTgjnQ2UuiaSonaTpBh1Dl0Owo6RPQCNfJDRHGUPWq/gX7h0vWQ
VAJs5fv/VsyhCOaIb76zT2YE+x1X8seW/hnnCH2aFCXKxxCOsI7N/9yEpYvktuic
6TE8y7G6YvDCgHZ0qU27N9vC6CMyTpRKw7IjIL7X65xy5en3WGf6adlL/78NP2Qr
Nmy/1wuP8Zn7
=5GyX
-----END PGP SIGNATURE-----
pgpMTNJ4RLQdF.pgp
Description: PGP signature
--- End Message ---