Your message dated Mon, 24 Aug 2026 22:32:23 +0000
with message-id <[email protected]>
and subject line Bug#1144465: fixed in libgit2 1.9.0+ds-2+deb13u1
has caused the Debian Bug report #1144465,
regarding libgit2: CVE-2026-5917
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144465: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144465
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libgit2
Version: 1.9.6+ds-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for libgit2.

CVE-2026-5917[0]:
| libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH
| backend (USE_SSH=libssh2) contain a shell command injection
| vulnerability that allows remote attackers to execute arbitrary
| commands on an SSH server by supplying a repository path containing
| unescaped shell metacharacters such as single quotes, semicolons, or
| pipes. The gen_proto() function in ssh_libssh2.c inserts the
| repository path directly into a shell command string without
| escaping special characters before passing it to
| libssh2_channel_exec(), enabling an attacker to craft a malicious
| submodule URL in a .gitmodules file that, when processed during a
| recursive clone, causes the remote server's shell to interpret
| injected commands under the victim's SSH user account.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5917
    https://www.cve.org/CVERecord?id=CVE-2026-5917
[1] 
https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: libgit2
Source-Version: 1.9.0+ds-2+deb13u1
Done: Timo Röhling <[email protected]>

We believe that the bug you reported is fixed in the latest version of
libgit2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Röhling <[email protected]> (supplier of updated libgit2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 20 Aug 2026 07:56:57 +0200
Source: libgit2
Architecture: source
Version: 1.9.0+ds-2+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Utkarsh Gupta <[email protected]>
Changed-By: Timo Röhling <[email protected]>
Closes: 1144465
Changes:
 libgit2 (1.9.0+ds-2+deb13u1) trixie-security; urgency=high
 .
   * Fix CVE-2026-5917: shell command injection in SSH transport
     (Closes: #1144465)
   * Fix CVE-2026-53583: inverted cert validity check for IP addresses
   * Fix CVE-2026-53584: unsanitized submodule paths
   * Fix CVE-2026-53585: limit pack object size to 2GiB
   * Fix CVE-2026-53586: pass correct hostname to auth layer after redirect
   * Fix CVE-2026-53587: read buffer overflow in capability check
Checksums-Sha1:
 38be9d61235f17fbf0e4f7ae0227c13cabfddd61 2349 libgit2_1.9.0+ds-2+deb13u1.dsc
 a17aa70d26da695678a2c110b343e4c5056d8fb1 4314236 libgit2_1.9.0+ds.orig.tar.xz
 6ec7322a050e5b9c1241a71c70c33aa1b07f53fd 24616 
libgit2_1.9.0+ds-2+deb13u1.debian.tar.xz
 458c1384ab0049f73e5125da5e24ec8bead0c5cc 8724 
libgit2_1.9.0+ds-2+deb13u1_amd64.buildinfo
Checksums-Sha256:
 b8a0c37f1a1f515d68c295408c533e48eb8050eba939ecd45b62bec1cac4bc89 2349 
libgit2_1.9.0+ds-2+deb13u1.dsc
 08f1f9137c4804ac4be4748f7141f8a6a9b7a12c942ac2fd4db5a28f8b65caa2 4314236 
libgit2_1.9.0+ds.orig.tar.xz
 009e775c3a2ba1c8128546c339e71df84f241f178919e006be1a6e1a37100941 24616 
libgit2_1.9.0+ds-2+deb13u1.debian.tar.xz
 c0ad27c1a41f68af961ed712ac0664d9f24ac742308ec4e403e10940187a15eb 8724 
libgit2_1.9.0+ds-2+deb13u1_amd64.buildinfo
Files:
 567f7a8788157f1f26710ee644c16820 2349 libs optional 
libgit2_1.9.0+ds-2+deb13u1.dsc
 d995b8616839b57d97ef7befcc457df6 4314236 libs optional 
libgit2_1.9.0+ds.orig.tar.xz
 0e4a9842eb1c7fb8c077bcf748b0771a 24616 libs optional 
libgit2_1.9.0+ds-2+deb13u1.debian.tar.xz
 7ed406d165b0695dafad18464ac2175e 8724 libs optional 
libgit2_1.9.0+ds-2+deb13u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEEmwPruYMA35fCsSO/zIxr3RQD9MoFAmqGm3UUHHJvZWhsaW5n
QGRlYmlhbi5vcmcACgkQzIxr3RQD9MrOMA//fOKg9X9i4IwUuQX6KmJfZF6BL6uM
XW3MxPSQegeBYLfKvVxHtFkHNxVBb0mwIbpDClhHnaFk2E5DD2LCIqWPnL4oq2Mc
Um2GUxSAla9QG2dm7BJmDKDlbwsDfK6qaiLkiFwGurHBo/6QY8ZK3J7AFOIdvCk0
jKWufyCx8CrSXbrxfWOQxMPZyVyC0pau6EvEXgcKvt2B9Dm/JKl6+yVTd5kP4H9b
yI21NSUpg3ohk4aV9jOD7utJXCBiPLmf2talyTvBvoehb0XjG7uwUeBNWiT7lh86
gs7Mj79ajbQjklM8FZD7X8lYVNIyRAlN+2p+vLT3EHAU+v4ex8SAQQwMFiRTXXjN
zOZwOtiYN+fcV65xT0SHHUoDh+pBxAqGOrxYa1gOKvWvw29QhreLyn/+C7QoW0aC
EkCE6e+nkDShMOcISCX1IdP7Rh5GGjknlWMfquq2OQnqatewXpux+cQb+Hqszsgf
b6s77L+mDieVSw3mFUnqxIVUjioBpg88E61J0o8qTOHFU4zmp1raoxGarOrNMW24
wAMOteUIYZP7mRy1PO+ImTBs8b7NDMMJDhWyiQaLHH0M2/pNwykMhVR9FZC+uNKh
yl3vMNp/EhVFvlZ04pGqJfPZZhSecTpaYWAmgKELv6G4oToVijtOBRgQM5C6gFB/
S0wiNR/x5o68log=
=cEk6
-----END PGP SIGNATURE-----

Attachment: pgpvbvxbQqXTa.pgp
Description: PGP signature


--- End Message ---

Reply via email to