[ubuntu/jammy-updates] git 1:2.34.1-1ubuntu1.16 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Wed Feb 25 16:58:46 UTC 2026


git (1:2.34.1-1ubuntu1.16) jammy-security; urgency=medium

  * SECURITY REGRESSION: Broken safe.directory access from CVE-2022-24765
    (LP: #2142239)
    - debian/patches/CVE-2022-24765-fix1.patch: Add protected_config,
      read_protected_config, and git_protected_config in config.c, config.h.
      Add upload_pack_protected_config in upload-pack.c. Modify test in
      t/t5544-pack-objects-hook.sh.
    - debian/patches/CVE-2022-24765-fix2.patch: Replace read_very_early_config
      with git_protected_config in setup.c.

Date: 2026-02-19 21:07:11.248650+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/git/1:2.34.1-1ubuntu1.16
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list