Your message dated Sun, 16 Aug 2026 12:51:51 +0000
with message-id <[email protected]>
and subject line Bug#1144465: fixed in libgit2 1.9.7+ds-1
has caused the Debian Bug report #1144465,
regarding libgit2: CVE-2026-5917
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144465: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144465
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libgit2
Version: 1.9.6+ds-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for libgit2.

CVE-2026-5917[0]:
| libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH
| backend (USE_SSH=libssh2) contain a shell command injection
| vulnerability that allows remote attackers to execute arbitrary
| commands on an SSH server by supplying a repository path containing
| unescaped shell metacharacters such as single quotes, semicolons, or
| pipes. The gen_proto() function in ssh_libssh2.c inserts the
| repository path directly into a shell command string without
| escaping special characters before passing it to
| libssh2_channel_exec(), enabling an attacker to craft a malicious
| submodule URL in a .gitmodules file that, when processed during a
| recursive clone, causes the remote server's shell to interpret
| injected commands under the victim's SSH user account.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5917
    https://www.cve.org/CVERecord?id=CVE-2026-5917
[1] 
https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libgit2
Source-Version: 1.9.7+ds-1
Done: Timo Röhling <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libgit2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Röhling <[email protected]> (supplier of updated libgit2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 16 Aug 2026 14:38:25 +0200
Source: libgit2
Architecture: source
Version: 1.9.7+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Utkarsh Gupta <[email protected]>
Changed-By: Timo Röhling <[email protected]>
Closes: 1144465
Changes:
 libgit2 (1.9.7+ds-1) unstable; urgency=medium
 .
   * New upstream version 1.9.7+ds
     - Fix CVE-2026-5917: shell command injection vulnerability
       (Closes: #1144465)
Checksums-Sha1:
 c7ce7b9f57a43bb593769cddc0c7152e5556ddd6 2767 libgit2_1.9.7+ds-1.dsc
 9cba431175927494f87c2617f2d625cc26de3e55 4327844 libgit2_1.9.7+ds.orig.tar.xz
 d44c3bca24184d676eb658da6e39059a329c4490 22624 libgit2_1.9.7+ds-1.debian.tar.xz
Checksums-Sha256:
 4013cf45109ee64f9ce86c32931a08ac35951ade605d55a34710afedf9563612 2767 
libgit2_1.9.7+ds-1.dsc
 9fa36a88e816cebe0fa9b526800f24550a46de248b989b1560de0990fb8746cc 4327844 
libgit2_1.9.7+ds.orig.tar.xz
 14c763f33001017ab80af6053af06623769ba72508fa70436838f19e40c3b282 22624 
libgit2_1.9.7+ds-1.debian.tar.xz
Files:
 25e3d4d84fd9ac6151a6193778fddffa 2767 libs optional libgit2_1.9.7+ds-1.dsc
 0052b092c6ec0b4fa521e3188984bba1 4327844 libs optional 
libgit2_1.9.7+ds.orig.tar.xz
 e96b5abdfd0bee76fc885af7d2804971 22624 libs optional 
libgit2_1.9.7+ds-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEmwPruYMA35fCsSO/zIxr3RQD9MoFAmqBsLwACgkQzIxr3RQD
9Mos5w//cc/i0f5gQe7DVqb+l9TobU83coRF1QVIaVqL8NO0lLf6Kj8bCgQeNfmZ
jWm/p2koRU6xhhjYmFtEDDxar3YguGd5hPqgw2jIJf4Ivn7BGoI0SU5KPVvDEIw/
jcnyrfI6X3uKanp4paKDTTRLwFmW/iYSnp+5YPSuJ2aMjtFhViKws6evNCJUkvPf
LgduIsV6eR/HdFCWiN4FIl+sltEu0kyXlMeLZvWQxtFwuOJci8aPT2LCyemApmYm
ogqUmxWxfv95jAkChSr2KwscXOmdJ+ZnCVh3xjDDpwutFSmZ9hMHAuDpBdnvQ17P
f6vVYANMWsYaTc38MD2CSTxCcUgoHXs9ivKT1kd+7WEZgQZVJaFYro0bDhP/DtPS
OVI90ngBjU2XDezPQJk/Q9/xNtcMayzB0plUrySntqAekyBu36vHcnrIUpqqYpov
XFCmxOFP6De0TK2XlTbjXWS6zPqzIB0pb1VSQ1YcX58TgzG93Q3TtAzJSyfdIAuJ
Qz515UMX77q1kVhhwb8ubqRaNR2RLszX3tU0i2IgjwkVeJdP+FwJCvuUPW7hCyHW
LmTHtSENvZH16krpjypnmv02oBLRRTNK2ZdCk8RHpl6g2kQ3p7+mt1l7r8EXUSj4
UbnpH8KkufKTgwUjsR+jmtC7Aaa0rCNBGA3arLinQT4SqD/DR9E=
=pu4K
-----END PGP SIGNATURE-----

Attachment: pgpSM_r2GEhMP.pgp
Description: PGP signature


--- End Message ---

Reply via email to