← All stories
● Covered by 2 sources · 2 reportsMedium impact

Git Commit Signature Malleability Allows Tampered Verified Commit Hashes

🔄 Updated 86d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Git commit hashes can be manipulated without access to signing keys.
  • Malleability allows identical content under new hashes with valid signatures.
  • Impacts systems relying on commit hash integrity such as version control.
  • No changes needed in repositories; inherent Git feature issue.

Overview of Git Hash Malleability

Researchers have identified a vulnerability in Git commit signing, known as "hash chain malleability," which affects the reliability of commit hashes. This flaw allows attackers to manipulate commit hashes while retaining identical content, metadata, and valid signatures from platforms like GitHub.

Technical Details

The flaw is exploited using methods like algebraic inversion for ECDSA, structural insertion for RSA and EdDSA, and non-canonical DER length re-encoding within the CMS. Despite altering the commit hash, all other aspects of the commit remain unchanged.

Even without access to the signing keys, one can create a duplicate commit that appears "Verified" by services like GitHub, complicating systems reliant on unique commit hashes.

Impact on Systems

This issue poses risks to dependency management, version control systems, and reproducible builds that treat commit hashes as immutable identifiers. Systems blocking commits via hashes may allow attackers to bypass restrictions with a new, validly signed hash of the same content.

Though no CVE or vendor advisory exists, the flaw does highlight a fundamental issue in the Git commit signature mechanism that could affect software integrity across various ecosystems.

Looking Forward

Stakeholders in software delivery pipelines should be aware of this vulnerability and consider its implications for their security practices. While no immediate patch is available, recognizing the limitation is crucial for maintaining software integrity and trust in version control systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

New research indicates that a signed Git commit's hash can be altered without invalidating its 'Verified' status on GitHub. This allows attackers to potentially bypass preventions based on commit hashes, posing risks to version control and repository integrity.

A study has demonstrated that Git commit signatures can be manipulated to produce distinct commits with identical content and valid signatures. This "hash chain malleability" poses risks to various systems relying on the integrity of commit hashes, such as dependency management and reproducible builds.