Debian Package Tracker
Register | Log in
Subscribe

libgit2

Choose email to subscribe with

general
  • source: libgit2 (main)
  • version: 1.9.7+ds-1
  • maintainer: Utkarsh Gupta (DMD)
  • uploaders: Pirate Praveen [DMD] – Mohammed Bilal [DMD] – Timo Röhling [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.1.0+dfsg.1-4+deb11u2
  • o-o-sec: 1.1.0+dfsg.1-4+deb11u2
  • oldstable: 1.5.1+ds-1+deb12u1
  • old-sec: 1.5.1+ds-1+deb12u1
  • old-bpo: 1.8.4+ds-3~bpo12+1
  • stable: 1.9.0+ds-2
  • testing: 1.9.6+ds-1
  • unstable: 1.9.7+ds-1
versioned links
  • 1.1.0+dfsg.1-4+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.5.1+ds-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.4+ds-3~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.0+ds-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.6+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.7+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libgit2-1.9
  • libgit2-dev
  • libgit2-experimental-dev
  • libgit2-experimental1.9
  • libgit2-fixtures
action needed
6 security issues in trixie high

There are 6 open security issues in trixie.

1 important issue:
  • CVE-2026-5917: libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.
5 issues left for the package maintainer to handle:
  • CVE-2026-53583: (needs triaging)
  • CVE-2026-53584: (needs triaging)
  • CVE-2026-53585: (needs triaging)
  • CVE-2026-53586: (needs triaging)
  • CVE-2026-53587: (needs triaging)

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-30 Last update: 2026-08-16 17:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-5917: libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.
Created: 2026-08-15 Last update: 2026-08-16 17:30
6 security issues in bullseye high

There are 6 open security issues in bullseye.

6 important issues:
  • CVE-2026-5917: libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.
  • CVE-2026-53583:
  • CVE-2026-53584:
  • CVE-2026-53585:
  • CVE-2026-53586:
  • CVE-2026-53587:
Created: 2026-07-30 Last update: 2026-08-16 17:30
6 security issues in bookworm high

There are 6 open security issues in bookworm.

6 important issues:
  • CVE-2026-5917: libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.
  • CVE-2026-53583:
  • CVE-2026-53584:
  • CVE-2026-53585:
  • CVE-2026-53586:
  • CVE-2026-53587:
Created: 2026-07-30 Last update: 2026-08-16 17:30
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for libgit2 (1.9.6+ds-1 to 1.9.7+ds-1): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest for git-evtag/2022.1-3: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libgit-raw-perl/0.90+ds-3: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libgit2/1.9.7+ds-1: amd64: No tests, superficial or marked flaky ♻ (reference ♻), arm64: No tests, superficial or marked flaky ♻, armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: Test triggered
    • ∙ ∙ Autopkgtest for libgit2-glib/1.2.1-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for nix/2.34.8+dfsg-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for python-pygit2/1.19.3-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-bat/0.26.1+dfsg-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-broot/1.57.0+dfsg-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-cargo-c/0.10.16-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-debcargo/2.8.3-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-eza/0.23.4-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-git-absorb/0.9.0-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-libgit2-sys/0.18.7+ds-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-sequoia-git/0.6.0-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rustc/1.95.0+dfsg1-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Updating libgit2 will fix bugs in testing: #1144465
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/libg/libgit2.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-08-16] Accepted libgit2 1.9.7+ds-1 (source) into unstable (Timo Röhling)
  • [2026-07-28] libgit2 1.9.6+ds-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-22] Accepted libgit2 1.9.6+ds-1 (source) into unstable (Timo Röhling)
  • [2026-06-08] libgit2 1.9.4+ds-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-31] Accepted libgit2 1.9.4+ds-1 (source) into unstable (Timo Röhling)
  • [2026-05-31] libgit2 1.9.3+ds-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-06] Accepted libgit2 1.9.3+ds-1 (source) into unstable (Timo Röhling)
  • [2026-05-02] libgit2 1.9.2+ds-9 MIGRATED to testing (Debian testing watch)
  • [2026-04-27] Accepted libgit2 1.9.2+ds-9 (source) into unstable (Timo Röhling)
  • [2026-04-24] Accepted libgit2 1.9.2+ds-8 (source) into unstable (Timo Röhling)
  • [2026-04-24] Accepted libgit2 1.9.2+ds-7 (source) into unstable (Timo Röhling)
  • [2026-02-20] libgit2 1.9.2+ds-6 MIGRATED to testing (Debian testing watch)
  • [2026-02-12] Accepted libgit2 1.9.2+ds-6 (source) into unstable (Timo Röhling)
  • [2026-01-27] libgit2 1.9.2+ds-5 MIGRATED to testing (Debian testing watch)
  • [2026-01-22] Accepted libgit2 1.9.2+ds-5 (source) into unstable (Timo Röhling)
  • [2026-01-21] Accepted libgit2 1.9.2+ds-4 (source) into unstable (Timo Röhling)
  • [2026-01-08] Accepted libgit2 1.9.2+ds-3 (all amd64 source) into experimental (Debian FTP Masters) (signed by: Timo Röhling)
  • [2026-01-02] libgit2 1.9.2+ds-2 MIGRATED to testing (Debian testing watch)
  • [2025-12-30] Accepted libgit2 1.9.2+ds-2 (source) into unstable (Timo Röhling)
  • [2025-12-30] Accepted libgit2 1.9.2+ds-1 (all amd64 source) into unstable (Timo Röhling)
  • [2025-08-17] libgit2 1.9.1+ds-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-13] Accepted libgit2 1.9.1+ds-1 (source) into unstable (Timo Röhling)
  • [2025-04-08] libgit2 1.9.0+ds-2 MIGRATED to testing (Debian testing watch)
  • [2025-04-03] Accepted libgit2 1.9.0+ds-2 (source) into unstable (Timo Röhling)
  • [2025-01-20] Accepted libgit2 1.8.4+ds-3~bpo12+1 (source) into stable-backports (Michael Tokarev)
  • [2025-01-20] Accepted libgit2 1.8.4+ds-3~bpo12+1~bin (source amd64 all) into stable-backports (Debian FTP Masters) (signed by: Michael Tokarev)
  • [2025-01-13] Accepted libgit2 1.9.0+ds-1 (all amd64 source) into experimental (Debian FTP Masters) (signed by: Timo Röhling)
  • [2024-11-30] libgit2 1.8.4+ds-3 MIGRATED to testing (Debian testing watch)
  • [2024-11-27] Accepted libgit2 1.8.4+ds-3 (source) into unstable (Timo Röhling)
  • [2024-11-23] libgit2 1.8.4+ds-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.9.6+ds-1ubuntu1
  • patches for 1.9.6+ds-1ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing