Bug 2514518

Summary: CVE-2026-5917 libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend [epel-all]
Product: [Fedora] Fedora EPEL Reporter: Ganesh <gnaik>
Component: libgit2_1.9Assignee: Fabio Valentini <decathorpe>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: epel10CC: alf.henrik.sauge, decathorpe, i, infra-sig, sgallagh
Target Milestone: ---Keywords: Reopened, Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["bf1b81d9-4fec-4354-8234-5cf1cd665927"]}
Fixed In Version: libgit2_1.9-1.9.7-1.el10_3 libgit2_1.9-1.9.7-1.el9 libgit2_1.9-1.9.7-1.el10_2 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-08-23 00:25:58 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2514416    

Description Ganesh 2026-08-12 08:16:48 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.

Comment 1 Stephen Gallagher 2026-08-13 18:22:46 UTC
We build with USE_SSH=no when %{rhel} is set (true for RHEL, CentOS Stream, EPEL and Fedora ELN), so this doesn't affect us on those platforms.

Comment 2 Fabio Valentini 2026-08-14 13:45:44 UTC
This is not correct, the bug *does* affect EPEL, it only does not affect ELN.

The "if rhel" conditional you mention is only present *for ELN* because SSH support is unwanted there.
But the epel10* and epel9 branches have SSH support enabled.

Comment 3 Stephen Gallagher 2026-08-14 15:01:21 UTC
My apologies, I only checked the `libgit2` package (https://src.fedoraproject.org/rpms/libgit2/blob/epel10/f/libgit2.spec) and neglected to check the versioned ones.

Comment 4 Fabio Valentini 2026-08-14 15:31:45 UTC
Moved to libgit2_1.9, which has the SSH support enabled.
The libgit2 package is still at v1.7 in EPEL, and has it disabled.

Submitted updates for 1.9.7 to EPEL 10.3, 10.2, and EPEL 9.

Comment 5 Fedora Update System 2026-08-14 15:32:07 UTC
FEDORA-EPEL-2026-da74b047d6 (libgit2_1.9-1.9.7-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-da74b047d6

Comment 6 Fedora Update System 2026-08-14 15:32:15 UTC
FEDORA-EPEL-2026-7671e4d4a3 (libgit2_1.9-1.9.7-1.el10_2) has been submitted as an update to Fedora EPEL 10.2.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7671e4d4a3

Comment 7 Fedora Update System 2026-08-14 15:32:30 UTC
FEDORA-EPEL-2026-a5f4b4222e (libgit2_1.9-1.9.7-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a5f4b4222e

Comment 8 Fedora Update System 2026-08-15 01:25:49 UTC
FEDORA-EPEL-2026-da74b047d6 has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-da74b047d6

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2026-08-15 01:31:34 UTC
FEDORA-EPEL-2026-a5f4b4222e has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a5f4b4222e

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2026-08-15 01:40:40 UTC
FEDORA-EPEL-2026-7671e4d4a3 has been pushed to the Fedora EPEL 10.2 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7671e4d4a3

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Fedora Update System 2026-08-23 00:25:58 UTC
FEDORA-EPEL-2026-da74b047d6 (libgit2_1.9-1.9.7-1.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 12 Fedora Update System 2026-08-23 00:40:53 UTC
FEDORA-EPEL-2026-a5f4b4222e (libgit2_1.9-1.9.7-1.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 13 Fedora Update System 2026-08-23 00:54:23 UTC
FEDORA-EPEL-2026-7671e4d4a3 (libgit2_1.9-1.9.7-1.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository.
If problem still persists, please make note of it in this bug report.