CVE-2026-53585

EUVD-2026-63548
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in src/libgit2/delta.c trusts the attacker-controlled res_sz value parsed by hdr_sz from a delta object header and passes that amount to git__malloc before validating delta instructions. Malicious pack data supplied through git_clone, git_fetch, git_remote_fetch, git_indexer_append, or a local attacker-supplied repository can use a very small multi-level OFS_DELTA chain to retain extremely large allocations and exhaust memory. This issue is fixed in versions 1.8.6 and 1.9.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libgit2libgit2
𝑥
< 1.8.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
libgit2
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.9.6+ds-1
fixed
sid
1.9.7+ds-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgit2
bionic
Fixed 0.26.0+dfsg.1-1.1ubuntu0.2+esm2
released
focal
Fixed 0.28.4+dfsg.1-2ubuntu0.1+esm1
released
jammy
Fixed 1.1.0+dfsg.1-4.1ubuntu0.1+esm1
released
noble
Fixed 1.7.2+ds-1ubuntu3.1
released
resolute
Fixed 1.9.1+ds-1ubuntu1.1
released
trusty
Fixed 0.19.0-2ubuntu0.4+esm2
released
xenial
Fixed 0.24.1-2ubuntu0.2+esm3
released
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cargo
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
cargo-c
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
cargo-c-debuginfo
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
cargo-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-cargo-c-debugsource
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
rust-debugger-common
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debugsource
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-doc
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-gdb
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-lldb
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-src
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-unknown-unknown
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-wasip1
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset-srpm-macros
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed