¡¾·ì϶¹«¸æ¡¿Git×ÓÄ£¿éõè¾¶»Ø³µ·ûµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶ (CVE-2025-48384)

°ä²¼¹¦·ò 2025-07-09

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Git×ÓÄ£¿éõè¾¶»Ø³µ·ûµ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶

CVE   ID

CVE-2025-48384

·ì϶ÀàÐÍ

ºÅÁîÖ´ÐÐ

·¢ÏÖ¹¦·ò

2025-07-09

·ì϶ÆÀ·Ö

8.0

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

¸ß

Óû§½»»¥

±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


GitÊÇÒ»¸öÉ¢²¼Ê½°æ±¾½ÚÔìϵͳ£¬ÓÃÓÚ¸ú×ÙÎļþ±ä¶¯²¢ºÏ×÷¿ª·¢Èí¼þ¡£ÓÉLinus TorvaldsÓÚ2005Äê´´½¨£¬GitÔʺܶà¸ö¿ª·¢Õß²¢Ðй¤×÷£¬ÖÎÀíÔ´´úÂ뺹Çà¼Í¼¡£ËüÖ§³Ö±¾µØ²Ù×÷£¬Óû§ÎÞÐèÏνӵ½ÖÐÑë·þÎñÆ÷¼´¿É½øÐа汾½ÚÔì¡£GitµÄÖ÷ÌâÌØµãÔ̺¬¸ßЧµÄ·ÖÖ§ÖÎÀí¡¢¹é²¢Ö°ÄÜ¡¢ÒÔ¼°Ö§³Ö´ó¹æÄ£ÏîÖ÷ÕÅÄÜÁ¦¡£Í¨¹ýºÅÁîÐкÍͼÐνçÃæ¹¤¾ß£¨ÈçGitHub Desktop£©Äܹ»ÓëGit²Ö¿â½øÐн»»¥£¬¿í·ºÀûÓÃÓÚ¿ªÔ´ºÍ˽ÓÐÈí¼þÏîÄ¿ÖС£


2025Äê7ÔÂ8ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½GitÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬Ó°ÏìÀàUnixƽ̨¡£¸Ã·ì϶ԴÓÚGitÅäÖÃÎļþ¶Ô»Ø³µ·û£¨CR£©µÄ´¦Öò»µ±¡£ÔÚʹÓÃgit clone --recursiveºÅÁîʱ£¬Git»á´Ó.gitmodulesÎļþ¶ÁÈ¡×ÓÄ£¿éõè¾¶²¢¼ì³öÏàÓ¦µÄ×ÓÄ£¿é¡£È»¶ø£¬Èô×ÓÄ£¿éõè¾¶Ô̺¬Î²²¿»Ø³µ·û£¨^M£©£¬Git»áÃýÎ󵨴¦ÖøÃõè¾¶£¬µ¼Ö»سµ·ûÃÔʧ²¢½«õ辶дÈë.git/modules/foo/configÖУ¬½ø¶øÊ¹×ÓÄ£¿é±»¼ì³öµ½ÃýÎóõè¾¶¡£Èô´æÔÚ·ûºÅÁ´½ÓÖ¸ÏòÃýÎóõè¾¶£¬²¢ÇÒ×ÓÄ£¿éÔ̺¬¿ÉÖ´ÐеÄpost-checkout¹³×Ӿ籾£¬¸Ã¾ç±¾¿ÉÄÜÔÚ¼ì³öʱÒâ±íÖ´ÐУ¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£´Ë·ì϶¿É±»ÀûÓÃͨ¹ý¶ñÒâÅú¸Ä.gitmodulesÎļþ»ò×¢Èë»Ø³µ·ûÀ´½ÚÔì×ÓÄ£¿é¼ì³ö¹ý³Ì¡£


¶þ¡¢Ó°ÏìÁìÓò


Git <= 2.50.0


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´°æ±¾£¬½¨ÒéÓû§Éý¼¶ÖÁÈçϰ汾
Git >= 2.43.7
Git >= 2.44.4
Git >= 2.45.4
Git >= 2.46.4
Git >= 2.47.3
Git >= 2.48.2
Git >= 2.49.1
Git >= 2.50.1


ÏÂÔØÁ´½Ó£ºhttps://github.com/git/git/tags


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9
https://nvd.nist.gov/vuln/detail/CVE-2025-48384