Back to Security Advisories
High 2026-07-15

Git-Lfs Security Update — AlmaLinux 9 (ALSA-2026:39319)

AlmaLinux 9

Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)…

Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)…

Type:
security

Severity:
important

Release date:
2026-07-15

Description:
Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 git-lfs-3.7.1-4.el9_8.2.aarch64.rpm 3eeec315a464d52e4f899ae33cbcfcab0755de79b2db82b248af912dcf122e40
ppc64le git-lfs-3.7.1-4.el9_8.2.ppc64le.rpm c1ccab30254ed16a6c535e2916a07a64ce0c1949fd7c5e2de0b8d8447cdda9b6
s390x git-lfs-3.7.1-4.el9_8.2.s390x.rpm 4db731ddb4c4de635f423e3b0aa827b4c16b954b497261b117bb11467363a862
x86_64 git-lfs-3.7.1-4.el9_8.2.x86_64.rpm af245d13d42a201fe9781605e80d970ef0c8b0c9c02d14c4babf8ee901314ae6

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System