CVE-2026-47191 - kas checks out SHA-like git branches as valid commits
Brief
CVE ID : CVE-2026-47191
Published : Aug. 14, 2026, 4:35 p. m.
- 30 minutes ago
Description : kas is a setup tool for bitbake based projects. Prior to version 5. 3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository.
This implies that the referenced repository has been taken over by an attacker and modified to carry such a branch. SHA-1 commits may also be replaced by creating hash collisions, so the primary impact of this issue is on SHA-256 commit IDs. Version 5. 3 fixes the issue.
As a workaround, avoid relying solely on the commit ID for integrity validation of a repository that might become under control of a malicious 3rd party.
