Researchers have identified a vulnerability in Git commit signing, known as "hash chain malleability," which affects the reliability of commit hashes. This flaw allows attackers to manipulate commit hashes while retaining identical content, metadata, and valid signatures from platforms like GitHub.
The flaw is exploited using methods like algebraic inversion for ECDSA, structural insertion for RSA and EdDSA, and non-canonical DER length re-encoding within the CMS. Despite altering the commit hash, all other aspects of the commit remain unchanged.
Even without access to the signing keys, one can create a duplicate commit that appears "Verified" by services like GitHub, complicating systems reliant on unique commit hashes.
This issue poses risks to dependency management, version control systems, and reproducible builds that treat commit hashes as immutable identifiers. Systems blocking commits via hashes may allow attackers to bypass restrictions with a new, validly signed hash of the same content.
Though no CVE or vendor advisory exists, the flaw does highlight a fundamental issue in the Git commit signature mechanism that could affect software integrity across various ecosystems.
Stakeholders in software delivery pipelines should be aware of this vulnerability and consider its implications for their security practices. While no immediate patch is available, recognizing the limitation is crucial for maintaining software integrity and trust in version control systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
New research indicates that a signed Git commit's hash can be altered without invalidating its 'Verified' status on GitHub. This allows attackers to potentially bypass preventions based on commit hashes, posing risks to version control and repository integrity.
A study has demonstrated that Git commit signatures can be manipulated to produce distinct commits with identical content and valid signatures. This "hash chain malleability" poses risks to various systems relying on the integrity of commit hashes, such as dependency management and reproducible builds.