#1144465 libgit2: CVE-2026-5917

Package:
src:libgit2
Source:
src:libgit2
Submitter:
Salvatore Bonaccorso
Date:
2026-08-24 22:33:03 UTC
Severity:
normal
Tags:
#1144465#5
Date:
2026-08-15 12:29:32 UTC
From:
To:
Hi,

The following vulnerability was published for libgit2.

CVE-2026-5917[0]:
| libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH
| backend (USE_SSH=libssh2) contain a shell command injection
| vulnerability that allows remote attackers to execute arbitrary
| commands on an SSH server by supplying a repository path containing
| unescaped shell metacharacters such as single quotes, semicolons, or
| pipes. The gen_proto() function in ssh_libssh2.c inserts the
| repository path directly into a shell command string without
| escaping special characters before passing it to
| libssh2_channel_exec(), enabling an attacker to craft a malicious
| submodule URL in a .gitmodules file that, when processed during a
| recursive clone, causes the remote server's shell to interpret
| injected commands under the victim's SSH user account.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5917
https://www.cve.org/CVERecord?id=CVE-2026-5917
[1] https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144465#18
Date:
2026-08-16 12:51:51 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libgit2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144465@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Röhling <roehling@debian.org> (supplier of updated libgit2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 16 Aug 2026 14:38:25 +0200
Source: libgit2
Architecture: source
Version: 1.9.7+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Utkarsh Gupta <utkarsh@debian.org>
Changed-By: Timo Röhling <roehling@debian.org>
Closes: 1144465
Changes:
 libgit2 (1.9.7+ds-1) unstable; urgency=medium
 .
   * New upstream version 1.9.7+ds
     - Fix CVE-2026-5917: shell command injection vulnerability
       (Closes: #1144465)
Checksums-Sha1:
 c7ce7b9f57a43bb593769cddc0c7152e5556ddd6 2767 libgit2_1.9.7+ds-1.dsc
 9cba431175927494f87c2617f2d625cc26de3e55 4327844 libgit2_1.9.7+ds.orig.tar.xz
 d44c3bca24184d676eb658da6e39059a329c4490 22624 libgit2_1.9.7+ds-1.debian.tar.xz
Checksums-Sha256:
 4013cf45109ee64f9ce86c32931a08ac35951ade605d55a34710afedf9563612 2767 libgit2_1.9.7+ds-1.dsc
 9fa36a88e816cebe0fa9b526800f24550a46de248b989b1560de0990fb8746cc 4327844 libgit2_1.9.7+ds.orig.tar.xz
 14c763f33001017ab80af6053af06623769ba72508fa70436838f19e40c3b282 22624 libgit2_1.9.7+ds-1.debian.tar.xz
Files:
 25e3d4d84fd9ac6151a6193778fddffa 2767 libs optional libgit2_1.9.7+ds-1.dsc
 0052b092c6ec0b4fa521e3188984bba1 4327844 libs optional libgit2_1.9.7+ds.orig.tar.xz
 e96b5abdfd0bee76fc885af7d2804971 22624 libs optional libgit2_1.9.7+ds-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEmwPruYMA35fCsSO/zIxr3RQD9MoFAmqBsLwACgkQzIxr3RQD
9Mos5w//cc/i0f5gQe7DVqb+l9TobU83coRF1QVIaVqL8NO0lLf6Kj8bCgQeNfmZ
jWm/p2koRU6xhhjYmFtEDDxar3YguGd5hPqgw2jIJf4Ivn7BGoI0SU5KPVvDEIw/
jcnyrfI6X3uKanp4paKDTTRLwFmW/iYSnp+5YPSuJ2aMjtFhViKws6evNCJUkvPf
LgduIsV6eR/HdFCWiN4FIl+sltEu0kyXlMeLZvWQxtFwuOJci8aPT2LCyemApmYm
ogqUmxWxfv95jAkChSr2KwscXOmdJ+ZnCVh3xjDDpwutFSmZ9hMHAuDpBdnvQ17P
f6vVYANMWsYaTc38MD2CSTxCcUgoHXs9ivKT1kd+7WEZgQZVJaFYro0bDhP/DtPS
OVI90ngBjU2XDezPQJk/Q9/xNtcMayzB0plUrySntqAekyBu36vHcnrIUpqqYpov
XFCmxOFP6De0TK2XlTbjXWS6zPqzIB0pb1VSQ1YcX58TgzG93Q3TtAzJSyfdIAuJ
Qz515UMX77q1kVhhwb8ubqRaNR2RLszX3tU0i2IgjwkVeJdP+FwJCvuUPW7hCyHW
LmTHtSENvZH16krpjypnmv02oBLRRTNK2ZdCk8RHpl6g2kQ3p7+mt1l7r8EXUSj4
UbnpH8KkufKTgwUjsR+jmtC7Aaa0rCNBGA3arLinQT4SqD/DR9E=
=pu4K
-----END PGP SIGNATURE-----

#1144465#23
Date:
2026-08-24 22:32:23 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libgit2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144465@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Röhling <roehling@debian.org> (supplier of updated libgit2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 20 Aug 2026 07:56:57 +0200
Source: libgit2
Architecture: source
Version: 1.9.0+ds-2+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Utkarsh Gupta <utkarsh@debian.org>
Changed-By: Timo Röhling <roehling@debian.org>
Closes: 1144465
Changes:
 libgit2 (1.9.0+ds-2+deb13u1) trixie-security; urgency=high
 .
   * Fix CVE-2026-5917: shell command injection in SSH transport
     (Closes: #1144465)
   * Fix CVE-2026-53583: inverted cert validity check for IP addresses
   * Fix CVE-2026-53584: unsanitized submodule paths
   * Fix CVE-2026-53585: limit pack object size to 2GiB
   * Fix CVE-2026-53586: pass correct hostname to auth layer after redirect
   * Fix CVE-2026-53587: read buffer overflow in capability check
Checksums-Sha1:
 38be9d61235f17fbf0e4f7ae0227c13cabfddd61 2349 libgit2_1.9.0+ds-2+deb13u1.dsc
 a17aa70d26da695678a2c110b343e4c5056d8fb1 4314236 libgit2_1.9.0+ds.orig.tar.xz
 6ec7322a050e5b9c1241a71c70c33aa1b07f53fd 24616 libgit2_1.9.0+ds-2+deb13u1.debian.tar.xz
 458c1384ab0049f73e5125da5e24ec8bead0c5cc 8724 libgit2_1.9.0+ds-2+deb13u1_amd64.buildinfo
Checksums-Sha256:
 b8a0c37f1a1f515d68c295408c533e48eb8050eba939ecd45b62bec1cac4bc89 2349 libgit2_1.9.0+ds-2+deb13u1.dsc
 08f1f9137c4804ac4be4748f7141f8a6a9b7a12c942ac2fd4db5a28f8b65caa2 4314236 libgit2_1.9.0+ds.orig.tar.xz
 009e775c3a2ba1c8128546c339e71df84f241f178919e006be1a6e1a37100941 24616 libgit2_1.9.0+ds-2+deb13u1.debian.tar.xz
 c0ad27c1a41f68af961ed712ac0664d9f24ac742308ec4e403e10940187a15eb 8724 libgit2_1.9.0+ds-2+deb13u1_amd64.buildinfo
Files:
 567f7a8788157f1f26710ee644c16820 2349 libs optional libgit2_1.9.0+ds-2+deb13u1.dsc
 d995b8616839b57d97ef7befcc457df6 4314236 libs optional libgit2_1.9.0+ds.orig.tar.xz
 0e4a9842eb1c7fb8c077bcf748b0771a 24616 libs optional libgit2_1.9.0+ds-2+deb13u1.debian.tar.xz
 7ed406d165b0695dafad18464ac2175e 8724 libs optional libgit2_1.9.0+ds-2+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEEmwPruYMA35fCsSO/zIxr3RQD9MoFAmqGm3UUHHJvZWhsaW5n
QGRlYmlhbi5vcmcACgkQzIxr3RQD9MrOMA//fOKg9X9i4IwUuQX6KmJfZF6BL6uM
XW3MxPSQegeBYLfKvVxHtFkHNxVBb0mwIbpDClhHnaFk2E5DD2LCIqWPnL4oq2Mc
Um2GUxSAla9QG2dm7BJmDKDlbwsDfK6qaiLkiFwGurHBo/6QY8ZK3J7AFOIdvCk0
jKWufyCx8CrSXbrxfWOQxMPZyVyC0pau6EvEXgcKvt2B9Dm/JKl6+yVTd5kP4H9b
yI21NSUpg3ohk4aV9jOD7utJXCBiPLmf2talyTvBvoehb0XjG7uwUeBNWiT7lh86
gs7Mj79ajbQjklM8FZD7X8lYVNIyRAlN+2p+vLT3EHAU+v4ex8SAQQwMFiRTXXjN
zOZwOtiYN+fcV65xT0SHHUoDh+pBxAqGOrxYa1gOKvWvw29QhreLyn/+C7QoW0aC
EkCE6e+nkDShMOcISCX1IdP7Rh5GGjknlWMfquq2OQnqatewXpux+cQb+Hqszsgf
b6s77L+mDieVSw3mFUnqxIVUjioBpg88E61J0o8qTOHFU4zmp1raoxGarOrNMW24
wAMOteUIYZP7mRy1PO+ImTBs8b7NDMMJDhWyiQaLHH0M2/pNwykMhVR9FZC+uNKh
yl3vMNp/EhVFvlZ04pGqJfPZZhSecTpaYWAmgKELv6G4oToVijtOBRgQM5C6gFB/
S0wiNR/x5o68log=
=cEk6
-----END PGP SIGNATURE-----