CVE-2026-53587

EUVD-2026-63547
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libgit2libgit2
𝑥
< 1.8.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
libgit2
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.9.6+ds-1
fixed
sid
1.9.7+ds-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgit2
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 1.7.2+ds-1ubuntu3.1
released
resolute
Fixed 1.9.1+ds-1ubuntu1.1
released
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cargo
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
cargo-c
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
cargo-c-debuginfo
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
cargo-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-cargo-c-debugsource
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
rust-debugger-common
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debugsource
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-doc
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-gdb
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-lldb
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-src
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-unknown-unknown
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-wasip1
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset-srpm-macros
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed