| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6453-1 | libgit2 security update |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 20 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libgit2
Libgit2 libgit2 |
|
| Vendors & Products |
Libgit2
Libgit2 libgit2 |
Thu, 20 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5. | |
| Title | libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data | |
| Weaknesses | CWE-125 CWE-126 CWE-1284 CWE-20 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T19:18:33.821Z
Reserved: 2026-06-09T19:11:53.484Z
Link: CVE-2026-53587
Updated: 2026-08-20T19:18:12.597Z
Status : Received
Published: 2026-08-20T19:16:55.137
Modified: 2026-08-20T20:17:34.557
Link: CVE-2026-53587
No data.
OpenCVE Enrichment
Updated: 2026-08-20T20:30:05Z
Debian DSA