USN-8628-1

Source
https://ubuntu.com/security/notices/USN-8628-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8628-1
Upstream
Related
Published
2026-08-12T19:13:07Z
Modified
2026-08-13T19:41:53.204214758Z
Summary
libgit2 vulnerabilities
Details

It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128)

It was discovered that libgit2 incorrectly handled empty packet lines in the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10129)

It was discovered that libgit2 incorrectly handled error reporting in the HTTP transport. A remote attacker could possibly use this issue to spoof servers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)

It was discovered that libgit2 incorrectly handled certain crafted "ng" packets. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-15501)

Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-8098)

Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)

Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled submodule paths. A remote attacker could possibly use this issue to write files outside the working tree. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53584)

Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled delta object result-size headers. A remote attacker could possibly use this issue to cause libgit2 to consume excessive memory, leading to a denial of service. (CVE-2026-53585)

Thai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects. A remote attacker could possibly use this issue to leak credentials to an offsite redirect target. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53586)

It was discovered that libgit2 incorrectly handled certain capability buffers in the smart protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53587)

References

Affected packages

Ubuntu:24.04:LTS
libgit2

Package

Name
libgit2
Purl
pkg:deb/ubuntu/libgit2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.2+ds-1ubuntu3.1

Affected versions

1.*
1.5.1+ds-1ubuntu1
1.7.1+ds-2ubuntu1
1.7.2+ds-1ubuntu1
1.7.2+ds-1ubuntu2
1.7.2+ds-1ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.7.2+ds-1ubuntu3.1",
            "binary_name": "libgit2-1.7"
        },
        {
            "binary_version": "1.7.2+ds-1ubuntu3.1",
            "binary_name": "libgit2-fixtures"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json"
cves_map
{
    "ecosystem": "Ubuntu:24.04:LTS",
    "cves": [
        {
            "id": "CVE-2026-53584",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53585",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53586",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53587",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ]
}
Ubuntu:26.04:LTS
libgit2

Package

Name
libgit2
Purl
pkg:deb/ubuntu/libgit2?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1+ds-1ubuntu1.1

Affected versions

1.*
1.9.0+ds-2ubuntu2
1.9.1+ds-1ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.9.1+ds-1ubuntu1.1",
            "binary_name": "libgit2-1.9"
        },
        {
            "binary_version": "1.9.1+ds-1ubuntu1.1",
            "binary_name": "libgit2-fixtures"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json"
cves_map
{
    "ecosystem": "Ubuntu:26.04:LTS",
    "cves": [
        {
            "id": "CVE-2026-53584",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53585",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53586",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53587",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ]
}
Ubuntu:Pro:14.04:LTS
libgit2

Package

Name
libgit2
Purl
pkg:deb/ubuntu/libgit2?arch=source&distro=esm-infra-legacy%2Ftrusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19.0-2ubuntu0.4+esm2

Affected versions

0.*
0.19.0-2
0.19.0-2ubuntu0.4
0.19.0-2ubuntu0.4+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.19.0-2ubuntu0.4+esm2",
            "binary_name": "libgit2-0"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:14.04:LTS",
    "cves": [
        {
            "id": "CVE-2016-10128",
            "severity": [
                {
                    "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2016-10129",
            "severity": [
                {
                    "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2018-8099",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "low",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2018-15501",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53585",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ]
}
Ubuntu:Pro:16.04:LTS
libgit2

Package

Name
libgit2
Purl
pkg:deb/ubuntu/libgit2?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.24.1-2ubuntu0.2+esm3

Affected versions

0.*
0.22.2-2
0.23.1-1
0.24.1-2
0.24.1-2ubuntu0.2
0.24.1-2ubuntu0.2+esm1
0.24.1-2ubuntu0.2+esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.24.1-2ubuntu0.2+esm3",
            "binary_name": "libgit2-24"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:16.04:LTS",
    "cves": [
        {
            "id": "CVE-2016-10128",
            "severity": [
                {
                    "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2016-10129",
            "severity": [
                {
                    "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2016-10130",
            "severity": [
                {
                    "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2018-8099",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "low",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2018-15501",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53585",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ]
}
Ubuntu:Pro:18.04:LTS
libgit2

Package

Name
libgit2
Purl
pkg:deb/ubuntu/libgit2?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.26.0+dfsg.1-1.1ubuntu0.2+esm2

Affected versions

0.*
0.25.1+really0.24.6-1
0.26.0+dfsg.1-1.1
0.26.0+dfsg.1-1.1build1
0.26.0+dfsg.1-1.1ubuntu0.2
0.26.0+dfsg.1-1.1ubuntu0.2+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.26.0+dfsg.1-1.1ubuntu0.2+esm2",
            "binary_name": "libgit2-26"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:18.04:LTS",
    "cves": [
        {
            "id": "CVE-2018-8098",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "low",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2018-8099",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "low",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2018-15501",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53585",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ]
}
Ubuntu:Pro:20.04:LTS
libgit2

Package

Name
libgit2
Purl
pkg:deb/ubuntu/libgit2?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.28.4+dfsg.1-2ubuntu0.1+esm1

Affected versions

0.*
0.27.7+dfsg.1-0.2build1
0.28.3+dfsg.1-1
0.28.3+dfsg.1-1ubuntu1
0.28.4+dfsg.1-2
0.28.4+dfsg.1-2ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.28.4+dfsg.1-2ubuntu0.1+esm1",
            "binary_name": "libgit2-28"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:20.04:LTS",
    "cves": [
        {
            "id": "CVE-2026-53584",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53585",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53586",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ]
}
Ubuntu:Pro:22.04:LTS
libgit2

Package

Name
libgit2
Purl
pkg:deb/ubuntu/libgit2?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.0+dfsg.1-4.1ubuntu0.1+esm1

Affected versions

1.*
1.1.0+dfsg.1-4
1.1.0+dfsg.1-4.1
1.1.0+dfsg.1-4.1build1
1.1.0+dfsg.1-4.1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.1.0+dfsg.1-4.1ubuntu0.1+esm1",
            "binary_name": "libgit2-1.1"
        },
        {
            "binary_version": "1.1.0+dfsg.1-4.1ubuntu0.1+esm1",
            "binary_name": "libgit2-fixtures"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8628-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:22.04:LTS",
    "cves": [
        {
            "id": "CVE-2026-53584",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53585",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2026-53586",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ]
}