news.mlab.sh
Back to the feed
threat-intel

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

High
Image: The Hacker News
Summary

A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verified" to GitHub. This is achieved by manipulating the signature data itself, bypassing traditional hash-based checks. The flaw stems from GitHub's failure to strictly canonicalize signatures before verifying them, allowing for the creation of valid, yet misleading, commits. This doesn't break SHA-256 or hash collisions, but it undermines the uniqueness of commit hashes and can be exploited to introduce malicious code.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.