Home / mailingsPDF  

[USN-8628-1] libgit2 vulnerabilities

Posted on 13 August 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8628-1
August 12, 2026

libgit2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in libgit2.

Software Description:
- libgit2: Portable C implementation of the Git core methods library

Details:

It was discovered that libgit2 incorrectly handled the Git Smart Protocol.
A remote attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2016-10128)

It was discovered that libgit2 incorrectly handled empty packet lines in
the Git Smart Protocol. A remote attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2016-10129)

It was discovered that libgit2 incorrectly handled error reporting in the
HTTP transport. A remote attacker could possibly use this issue to spoof
servers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)

It was discovered that libgit2 incorrectly handled certain crafted "ng"
packets. A remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
and Ubuntu 18.04 LTS. (CVE-2018-15501)

Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly
handled certain repository index files. A local attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
18.04 LTS. (CVE-2018-8098)

Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly
handled certain repository index files. A local attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)

Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2
incorrectly handled submodule paths. A remote attacker could possibly use
this issue to write files outside the working tree. This issue only
affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 26.04 LTS. (CVE-2026-53584)

Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2
incorrectly handled delta object result-size headers. A remote attacker
could possibly use this issue to cause libgit2 to consume excessive memory,
leading to a denial of service. (CVE-2026-53585)

Thai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.
A remote attacker could possibly use this issue to leak credentials to an
offsite redirect target. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-53586)

It was discovered that libgit2 incorrectly handled certain capability
buffers in the smart protocol. A remote attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 24.04
LTS and Ubuntu 26.04 LTS. (CVE-2026-53587)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libgit2-1.9 1.9.1+ds-1ubuntu1.1
libgit2-dev 1.9.1+ds-1ubuntu1.1
libgit2-fixtures 1.9.1+ds-1ubuntu1.1

Ubuntu 24.04 LTS
libgit2-1.7 1.7.2+ds-1ubuntu3.1
libgit2-dev 1.7.2+ds-1ubuntu3.1
libgit2-fixtures 1.7.2+ds-1ubuntu3.1

Ubuntu 22.04 LTS
libgit2-1.1 1.1.0+dfsg.1-4.1ubuntu0.1+esm1
Available with Ubuntu Pro
libgit2-dev 1.1.0+dfsg.1-4.1ubuntu0.1+esm1
Available with Ubuntu Pro
libgit2-fixtures 1.1.0+dfsg.1-4.1ubuntu0.1+esm1
Available with Ubuntu Pro

Ubuntu 20.04 LTS
libgit2-28 0.28.4+dfsg.1-2ubuntu0.1+esm1
Available with Ubuntu Pro
libgit2-dev 0.28.4+dfsg.1-2ubuntu0.1+esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libgit2-26 0.26.0+dfsg.1-1.1ubuntu0.2+esm2
Available with Ubuntu Pro
libgit2-dev 0.26.0+dfsg.1-1.1ubuntu0.2+esm2
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libgit2-24 0.24.1-2ubuntu0.2+esm3
Available with Ubuntu Pro
libgit2-dev 0.24.1-2ubuntu0.2+esm3
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libgit2-0 0.19.0-2ubuntu0.4+esm2
Available with Ubuntu Pro
libgit2-dev 0.19.0-2ubuntu0.4+esm2
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8628-1
CVE-2016-10128, CVE-2016-10129, CVE-2016-10130, CVE-2018-15501,
CVE-2018-8098, CVE-2018-8099, CVE-2026-53584, CVE-2026-53585,
CVE-2026-53586, CVE-2026-53587

Package Information:
https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1
https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1

--===============7992040984319901023==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP