USN-8628-1: libgit2 vulnerabilities
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128) It was discovered that libgit2 incorrectly handled empty packet lines in the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10129) It was discovered that libgit2 incorrectly handled error reporting in the HTTP transport. A remote attacker could possibly use this issue to spoof servers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130) It was discovered that libgit2 incorrectly handled certain crafted "ng" packets. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-15501) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-8098) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled submodule paths. A remote attacker could possibly use this issue to write files outside the working tree. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53584) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled delta object result-size headers. A remote attacker could possibly us
CSIRTS triage
- What
- libgit2 incorrectly handles Git Smart Protocol packets and HTTP error reporting, allowing remote code execution, denial of service, and server spoofing.
- Who is affected
- Systems running libgit2 on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and other distributions.
- Urgency
- Remote code execution potential makes this critical; exploit complexity and current exploitation status unclear.
- Action
- Apply security updates from your distribution and ensure libgit2 is patched to latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libgit2
Get an email when a new libgit2 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8628-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2016-101284.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 90% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2016-101293.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2016-101301.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2018-155014.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 90% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2018-80981.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 71% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2018-80991.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-535840.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-535850.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-535860.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-535870.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2016-10128 | coverage & exploitation status | NVD · CVE.org |
| CVE-2016-10129 | coverage & exploitation status | NVD · CVE.org |
| CVE-2016-10130 | coverage & exploitation status | NVD · CVE.org |
| CVE-2018-15501 | coverage & exploitation status | NVD · CVE.org |
| CVE-2018-8098 | coverage & exploitation status | NVD · CVE.org |
| CVE-2018-8099 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53584 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53585 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53586 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53587 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-53587: libgit2 is a portable C implementation of the Git core methods provided as a linkable library …nvd
- mediumCVE-2026-53586: libgit2 is a portable C implementation of the Git core methods provided as a linkable library …nvd
- mediumCVE-2026-53585: libgit2 is a portable C implementation of the Git core methods provided as a linkable library …nvd
- mediumCVE-2026-53584: libgit2 is a portable C implementation of the Git core methods provided as a linkable library …nvd
- lowDSA-6453-1 libgit2 - security updatedebian
- mediumCVE-2026-53584: libgit2: Submodule path traversalmsrc
More from Ubuntu Security Notices
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25
- unknownUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities2026-08-25
- unknownUSN-8658-3: Linux kernel vulnerabilities2026-08-25
- unknownUSN-8643-4: Linux kernel vulnerabilities2026-08-25