Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42305

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 8.8

Описание

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.protectHFS settings were looked up under a wrong option name and so user-set values were silently ignored, and core.protectNTFS only defaulted to true on Windows (Git upstream has defaulted it to true everywhere since CVE-2019-1353). Both have been corrected. Anyone who clones, fetches, or checks out an untrusted repository with Dulwich on Windows - either through the Dulwich CLI, porcelain.clone, or any downstream tool built on Dulwich - is impacted. POSIX clones are not directly exploitable (on POSIX \ is a literal filename byte), but a POSIX user can unknowingly propagate a malicious tree to Windows consumers via push or re-publication. This issue is fixed in Dulwich 1.2.5. Users should upgrade to 1.2.5 or later. There is no effective pre-patch workaround. On affected versions the core.protectNTFS configuration key was silently ignored, so setting it to true does not mitigate the issue. Users who cannot upgrade should avoid cloning, fetching, or checking out untrusted repositories with Dulwich on Windows. After upgrading the NTFS validator is on by default on every platform, so no additional configuration is required.

A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious Git repository. This could lead to an arbitrary file write, ultimately resulting in remote code execution on the affected system.

Отчет

This is an Important flaw in Dulwich, a Python Git library, primarily impacting Windows systems. While Red Hat Enterprise Linux and other POSIX-based Red Hat products are not directly vulnerable to remote code execution, they can serve as vectors for propagating malicious Git repositories to Windows clients. Exploitation occurs when a user clones or checks out a specially crafted repository on a Windows system, leading to arbitrary file write and potential remote code execution. Red Hat Satellite ships the python-dulwich package however, this flaw primarily affects Dulwich when cloning or checking out a malicious Git repository on Windows, where NTFS path handling can lead to arbitrary file write and remote code execution. Red Hat Satellite runs on Red Hat Enterprise Linux and other POSIX platforms, where this Windows-specific path behavior does not apply. Therefore, Red Hat Satellite is not directly affected by this vulnerability.

Меры по смягчению последствий

Mitigation for this issue involves avoiding the cloning, fetching, or checking out of untrusted Git repositories with Dulwich. This operational control is crucial for preventing the introduction and propagation of malicious content, especially when Red Hat systems interact with or serve Windows clients that utilize Dulwich.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/controller-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/eda-controller-rhel9Not affected
Red Hat Enterprise Linux 7resource-agentsNot affected
Red Hat Enterprise Linux 8resource-agentsNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-autogluon-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2487758dulwich: Dulwich: Remote Code Execution via Malicious Git Repository

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
2 месяца назад

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.protectHFS settings were looked up under a wrong option name and so user-set values were silently ignored, and core.protectNTFS only defaulted to true on Windows (Git upstream has defaulted it to true everywhere since CVE-2019-1353). Both have been corrected. Anyone who clones, fetches, or checks out an untrusted repository with Dulwich on Windows - either through the Dulwich CLI, porcelain.clone, or any downstream tool built on Dulwich - is impacted. POSIX clones are not directly exploitable (on POSIX \ is a lite...

CVSS3: 8.8
nvd
2 месяца назад

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.protectHFS settings were looked up under a wrong option name and so user-set values were silently ignored, and core.protectNTFS only defaulted to true on Windows (Git upstream has defaulted it to true everywhere since CVE-2019-1353). Both have been corrected. Anyone who clones, fetches, or checks out an untrusted repository with Dulwich on Windows - either through the Dulwich CLI, porcelain.clone, or any downstream tool built on Dulwich - is impacted. POSIX clones are not directly exploitable (on POSIX \ is a literal

CVSS3: 8.8
debian
2 месяца назад

Dulwich is a pure-Python implementation of the Git file formats and pr ...

CVSS3: 8.8
github
2 месяца назад

Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows

8.8 High

CVSS3

Уязвимость CVE-2026-42305