CVE-2018-15501
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128) It was discovered that libgit2 incorrectly handled empty packet lines in the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10129) It was discovered that libgit2 incorrectly handled error reporting in the HTTP transport. A remote attacker could possibly use this issue to spoof servers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130) It was discovered that libgit2 incorrectly handled certain crafted "ng" packets. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-15501) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-8098) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled submodule paths. A remote attacker could possibly use this issue to write files outside the working tree. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53584) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled delta object result-size headers. A remote attacker could possibly us
CSIRTS triage
- What
- libgit2 incorrectly handles Git Smart Protocol packets and HTTP error reporting, allowing remote code execution, denial of service, and server spoofing.
- Who is affected
- Systems running libgit2 on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and other distributions.
- Urgency
- Remote code execution potential makes this critical; exploit complexity and current exploitation status unclear.
- Action
- Apply security updates from your distribution and ensure libgit2 is patched to latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2018-15501
Get an email if CVE-2018-15501 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk4.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 90% of all EPSS-scored CVEs.
Advisory coverage (1)
- unknownUSN-8628-1: libgit2 vulnerabilitiesubuntu · 2026-08-12
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2018-15501)