CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8628-1: libgit2 vulnerabilities

unknownpublic exploitCVE-2016-10128CVE-2016-10129CVE-2016-10130CVE-2018-15501CVE-2018-8098CVE-2018-8099
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128) It was discovered that libgit2 incorrectly handled empty packet lines in the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10129) It was discovered that libgit2 incorrectly handled error reporting in the HTTP transport. A remote attacker could possibly use this issue to spoof servers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130) It was discovered that libgit2 incorrectly handled certain crafted "ng" packets. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-15501) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-8098) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled submodule paths. A remote attacker could possibly use this issue to write files outside the working tree. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53584) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled delta object result-size headers. A remote attacker could possibly us

CSIRTS triage

vendor: libgit2product: libgit2Remote code executionDenial of serviceInformation disclosureaffected: affecting Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and later versions
What
libgit2 incorrectly handles Git Smart Protocol packets and HTTP error reporting, allowing remote code execution, denial of service, and server spoofing.
Who is affected
Systems running libgit2 on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and other distributions.
Urgency
Remote code execution potential makes this critical; exploit complexity and current exploitation status unclear.
Action
Apply security updates from your distribution and ensure libgit2 is patched to latest version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch libgit2

Get an email when a new libgit2 advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8628-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2016-10128coverage & exploitation statusNVD · CVE.org
CVE-2016-10129coverage & exploitation statusNVD · CVE.org
CVE-2016-10130coverage & exploitation statusNVD · CVE.org
CVE-2018-15501coverage & exploitation statusNVD · CVE.org
CVE-2018-8098coverage & exploitation statusNVD · CVE.org
CVE-2018-8099coverage & exploitation statusNVD · CVE.org
CVE-2026-53584coverage & exploitation statusNVD · CVE.org
CVE-2026-53585coverage & exploitation statusNVD · CVE.org
CVE-2026-53586coverage & exploitation statusNVD · CVE.org
CVE-2026-53587coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices