libgit2 vulnerabilities
Published: Wed, 12 Aug 2026 19:13
Summary
Several security issues were fixed in libgit2.
Details
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128) It was discovered that libgit2 incorrectly handled empty packet lines in the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10129) It was discovered that libgit2 incorrectly handled error reporting in the HTTP transport. A remote attacker could possibly use this issue to spoof servers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130) It was discovered that libgit2 incorrectly handled certain crafted "ng" packets. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-15501) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-8098) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled submodule paths. A remote attacker could possibly use this issue to write files outside the working tree. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53584) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled delta object result-size headers. A remote attacker could possibly use this issue to cause libgit2 to consume excessive memory, leading to a denial of service. (CVE-2026-53585) Thai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects. A remote attacker could possibly use this issue to leak credentials to an offsite redirect target. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53586) It was discovered that libgit2 incorrectly handled certain capability buffers in the smart protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53587)
Recommended actions per Ubuntu release
StackPatch playbook auto-generated per release codename and per affected package.
Ubuntu bionic
libgit2→0.26.0+dfsg.1-1.1ubuntu0.2+esm2apt_upgradeStandard apt upgrade. Install 0.26.0+dfsg.1-1.1ubuntu0.2+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-26→0.26.0+dfsg.1-1.1ubuntu0.2+esm2apt_upgradeStandard apt upgrade. Install 0.26.0+dfsg.1-1.1ubuntu0.2+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-26
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-dev→0.26.0+dfsg.1-1.1ubuntu0.2+esm2apt_upgradeStandard apt upgrade. Install 0.26.0+dfsg.1-1.1ubuntu0.2+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu focal
libgit2→0.28.4+dfsg.1-2ubuntu0.1+esm1apt_upgradeStandard apt upgrade. Install 0.28.4+dfsg.1-2ubuntu0.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-28→0.28.4+dfsg.1-2ubuntu0.1+esm1apt_upgradeStandard apt upgrade. Install 0.28.4+dfsg.1-2ubuntu0.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-28
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-dev→0.28.4+dfsg.1-2ubuntu0.1+esm1apt_upgradeStandard apt upgrade. Install 0.28.4+dfsg.1-2ubuntu0.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu jammy
libgit2→1.1.0+dfsg.1-4.1ubuntu0.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.0+dfsg.1-4.1ubuntu0.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-1.1→1.1.0+dfsg.1-4.1ubuntu0.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.0+dfsg.1-4.1ubuntu0.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-1.1
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-dev→1.1.0+dfsg.1-4.1ubuntu0.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.0+dfsg.1-4.1ubuntu0.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-fixtures→1.1.0+dfsg.1-4.1ubuntu0.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.0+dfsg.1-4.1ubuntu0.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-fixtures
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu noble
libgit2→1.7.2+ds-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 1.7.2+ds-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-1.7→1.7.2+ds-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 1.7.2+ds-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-1.7
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-dev→1.7.2+ds-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 1.7.2+ds-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-fixtures→1.7.2+ds-1ubuntu3.1apt_upgradeStandard apt upgrade. Install 1.7.2+ds-1ubuntu3.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-fixtures
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu resolute
libgit2→1.9.1+ds-1ubuntu1.1apt_upgradeStandard apt upgrade. Install 1.9.1+ds-1ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-1.9→1.9.1+ds-1ubuntu1.1apt_upgradeStandard apt upgrade. Install 1.9.1+ds-1ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-1.9
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-dev→1.9.1+ds-1ubuntu1.1apt_upgradeStandard apt upgrade. Install 1.9.1+ds-1ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-fixtures→1.9.1+ds-1ubuntu1.1apt_upgradeStandard apt upgrade. Install 1.9.1+ds-1ubuntu1.1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-fixtures
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu trusty
libgit2→0.19.0-2ubuntu0.4+esm2apt_upgradeStandard apt upgrade. Install 0.19.0-2ubuntu0.4+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-0→0.19.0-2ubuntu0.4+esm2apt_upgradeStandard apt upgrade. Install 0.19.0-2ubuntu0.4+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-0
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-dev→0.19.0-2ubuntu0.4+esm2apt_upgradeStandard apt upgrade. Install 0.19.0-2ubuntu0.4+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu xenial
libgit2→0.24.1-2ubuntu0.2+esm3apt_upgradeStandard apt upgrade. Install 0.24.1-2ubuntu0.2+esm3 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-24→0.24.1-2ubuntu0.2+esm3apt_upgradeStandard apt upgrade. Install 0.24.1-2ubuntu0.2+esm3 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-24
Most apt upgrades restart their service automatically. needrestart lists anything else.
libgit2-dev→0.24.1-2ubuntu0.2+esm3apt_upgradeStandard apt upgrade. Install 0.24.1-2ubuntu0.2+esm3 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libgit2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
Are YOU affected by USN-8628-1?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8628-1 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.