Git for Windows v2.53.0(3) 现已发布。这是一个安全修复版本,解决了 CVE-2026-32631 漏洞:
- CVE-2026-32631,Git for Windows:当用户克隆包含指向网络驱动器的符号链接的仓库时,Git 会在检出过程中跟随这些符号链接,导致 Windows 系统透明地执行 NTLM 身份验证,并将用户的 NTLMv2 哈希值泄露给攻击者控制的服务器。由于 NTLM 哈希算法本身存在安全漏洞,攻击者可以通过暴力破解的方式获取用户的凭据。此漏洞已通过阻止
git clone在检出过程中跟随指向网络驱动器的符号链接来解决。
| Filename |
SHA-256 |
| Git-2.53.0.3-64-bit.exe |
bc88381e192bd5b17a131755d837828d8a570da1ead89cfcde0d45ae38133c0b |
| Git-2.53.0.3-arm64.exe |
9cc821d1c402f4a5fd397ab0757ed67b7d91d3401ea171131acd745334056a9b |
| PortableGit-2.53.0.3-64-bit.7z.exe |
b365da794b1d2225eb24d5f5e09ef7792cfd5fa26c3a3586210280c80dff3a2a |
| PortableGit-2.53.0.3-arm64.7z.exe |
0db54010054c01f35501cf69e1e32d3710138ecb934d188bd77093afed24300e |
| MinGit-2.53.0.3-64-bit.zip |
0d7c85a26e45668b35d0d0aeb763289376cfc039e55e0938a617ed0dfa32e433 |
| MinGit-2.53.0.3-arm64.zip |
4e023ced9acba38d45b63cafadde57a11c754c0b46df8968117cd243f8f58ef4 |
| MinGit-2.53.0.3-32-bit.zip |
2a55bcec4de958570f4e27ae59dfa9f91d98c816113189e2fc6af8afe85ed66a |
| MinGit-2.53.0.3-busybox-64-bit.zip |
cab3a8dfb2bdd7328d79c0f8dbc934d038f755573ab22d4f72bcdd8ff9f86c26 |
| MinGit-2.53.0.3-busybox-32-bit.zip |
98ddcfe902949cfb656e2bc518f1053217d54d88a22317d02c026eda7aeeb984 |
| Git-2.53.0.3-64-bit.tar.bz2 |
1661f02e85a7901ad7920e2a358ee3772ed9066b00d8590bf2d9046ef10aa8b2 |
| Git-2.53.0.3-arm64.tar.bz2 |
4015f05a68bd2bcf3cc6c426e8d44b65d670fbb879225bb7b7c347cfc3a2758a |
更新说明:https://github.com/git-for-windows/git/releases/tag/v2.53.0.windows.3