#1144465 libgit2: CVE-2026-5917

Package:
src:libgit2
Source:
src:libgit2
Submitter:
Salvatore Bonaccorso
Date:
2026-08-16 12:53:02 UTC
Severity:
normal
Tags:
#1144465#5
Date:
2026-08-15 12:29:32 UTC
From:
To:
Hi,

The following vulnerability was published for libgit2.

CVE-2026-5917[0]:
| libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH
| backend (USE_SSH=libssh2) contain a shell command injection
| vulnerability that allows remote attackers to execute arbitrary
| commands on an SSH server by supplying a repository path containing
| unescaped shell metacharacters such as single quotes, semicolons, or
| pipes. The gen_proto() function in ssh_libssh2.c inserts the
| repository path directly into a shell command string without
| escaping special characters before passing it to
| libssh2_channel_exec(), enabling an attacker to craft a malicious
| submodule URL in a .gitmodules file that, when processed during a
| recursive clone, causes the remote server's shell to interpret
| injected commands under the victim's SSH user account.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5917
https://www.cve.org/CVERecord?id=CVE-2026-5917
[1] https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144465#18
Date:
2026-08-16 12:51:51 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libgit2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144465@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Röhling <roehling@debian.org> (supplier of updated libgit2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 16 Aug 2026 14:38:25 +0200
Source: libgit2
Architecture: source
Version: 1.9.7+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Utkarsh Gupta <utkarsh@debian.org>
Changed-By: Timo Röhling <roehling@debian.org>
Closes: 1144465
Changes:
 libgit2 (1.9.7+ds-1) unstable; urgency=medium
 .
   * New upstream version 1.9.7+ds
     - Fix CVE-2026-5917: shell command injection vulnerability
       (Closes: #1144465)
Checksums-Sha1:
 c7ce7b9f57a43bb593769cddc0c7152e5556ddd6 2767 libgit2_1.9.7+ds-1.dsc
 9cba431175927494f87c2617f2d625cc26de3e55 4327844 libgit2_1.9.7+ds.orig.tar.xz
 d44c3bca24184d676eb658da6e39059a329c4490 22624 libgit2_1.9.7+ds-1.debian.tar.xz
Checksums-Sha256:
 4013cf45109ee64f9ce86c32931a08ac35951ade605d55a34710afedf9563612 2767 libgit2_1.9.7+ds-1.dsc
 9fa36a88e816cebe0fa9b526800f24550a46de248b989b1560de0990fb8746cc 4327844 libgit2_1.9.7+ds.orig.tar.xz
 14c763f33001017ab80af6053af06623769ba72508fa70436838f19e40c3b282 22624 libgit2_1.9.7+ds-1.debian.tar.xz
Files:
 25e3d4d84fd9ac6151a6193778fddffa 2767 libs optional libgit2_1.9.7+ds-1.dsc
 0052b092c6ec0b4fa521e3188984bba1 4327844 libs optional libgit2_1.9.7+ds.orig.tar.xz
 e96b5abdfd0bee76fc885af7d2804971 22624 libs optional libgit2_1.9.7+ds-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEmwPruYMA35fCsSO/zIxr3RQD9MoFAmqBsLwACgkQzIxr3RQD
9Mos5w//cc/i0f5gQe7DVqb+l9TobU83coRF1QVIaVqL8NO0lLf6Kj8bCgQeNfmZ
jWm/p2koRU6xhhjYmFtEDDxar3YguGd5hPqgw2jIJf4Ivn7BGoI0SU5KPVvDEIw/
jcnyrfI6X3uKanp4paKDTTRLwFmW/iYSnp+5YPSuJ2aMjtFhViKws6evNCJUkvPf
LgduIsV6eR/HdFCWiN4FIl+sltEu0kyXlMeLZvWQxtFwuOJci8aPT2LCyemApmYm
ogqUmxWxfv95jAkChSr2KwscXOmdJ+ZnCVh3xjDDpwutFSmZ9hMHAuDpBdnvQ17P
f6vVYANMWsYaTc38MD2CSTxCcUgoHXs9ivKT1kd+7WEZgQZVJaFYro0bDhP/DtPS
OVI90ngBjU2XDezPQJk/Q9/xNtcMayzB0plUrySntqAekyBu36vHcnrIUpqqYpov
XFCmxOFP6De0TK2XlTbjXWS6zPqzIB0pb1VSQ1YcX58TgzG93Q3TtAzJSyfdIAuJ
Qz515UMX77q1kVhhwb8ubqRaNR2RLszX3tU0i2IgjwkVeJdP+FwJCvuUPW7hCyHW
LmTHtSENvZH16krpjypnmv02oBLRRTNK2ZdCk8RHpl6g2kQ3p7+mt1l7r8EXUSj4
UbnpH8KkufKTgwUjsR+jmtC7Aaa0rCNBGA3arLinQT4SqD/DR9E=
=pu4K
-----END PGP SIGNATURE-----