Bug 2514518 - CVE-2026-5917 libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend [epel-all]
Summary: CVE-2026-5917 libgit2: libgit2: Arbitrary code execution via shell command in...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: libgit2_1.9
Version: epel10
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Fabio Valentini
QA Contact:
URL:
Whiteboard: {"flaws": ["bf1b81d9-4fec-4354-8234-5...
Depends On:
Blocks: CVE-2026-5917
TreeView+ depends on / blocked
 
Reported: 2026-08-12 08:16 UTC by Ganesh
Modified: 2026-08-23 00:54 UTC (History)
5 users (show)

Fixed In Version: libgit2_1.9-1.9.7-1.el10_3 libgit2_1.9-1.9.7-1.el9 libgit2_1.9-1.9.7-1.el10_2
Clone Of:
Environment:
Last Closed: 2026-08-23 00:25:58 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-08-12 08:16:48 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.

Comment 1 Stephen Gallagher 2026-08-13 18:22:46 UTC
We build with USE_SSH=no when %{rhel} is set (true for RHEL, CentOS Stream, EPEL and Fedora ELN), so this doesn't affect us on those platforms.

Comment 2 Fabio Valentini 2026-08-14 13:45:44 UTC
This is not correct, the bug *does* affect EPEL, it only does not affect ELN.

The "if rhel" conditional you mention is only present *for ELN* because SSH support is unwanted there.
But the epel10* and epel9 branches have SSH support enabled.

Comment 3 Stephen Gallagher 2026-08-14 15:01:21 UTC
My apologies, I only checked the `libgit2` package (https://src.fedoraproject.org/rpms/libgit2/blob/epel10/f/libgit2.spec) and neglected to check the versioned ones.

Comment 4 Fabio Valentini 2026-08-14 15:31:45 UTC
Moved to libgit2_1.9, which has the SSH support enabled.
The libgit2 package is still at v1.7 in EPEL, and has it disabled.

Submitted updates for 1.9.7 to EPEL 10.3, 10.2, and EPEL 9.

Comment 5 Fedora Update System 2026-08-14 15:32:07 UTC
FEDORA-EPEL-2026-da74b047d6 (libgit2_1.9-1.9.7-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-da74b047d6

Comment 6 Fedora Update System 2026-08-14 15:32:15 UTC
FEDORA-EPEL-2026-7671e4d4a3 (libgit2_1.9-1.9.7-1.el10_2) has been submitted as an update to Fedora EPEL 10.2.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7671e4d4a3

Comment 7 Fedora Update System 2026-08-14 15:32:30 UTC
FEDORA-EPEL-2026-a5f4b4222e (libgit2_1.9-1.9.7-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a5f4b4222e

Comment 8 Fedora Update System 2026-08-15 01:25:49 UTC
FEDORA-EPEL-2026-da74b047d6 has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-da74b047d6

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2026-08-15 01:31:34 UTC
FEDORA-EPEL-2026-a5f4b4222e has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a5f4b4222e

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2026-08-15 01:40:40 UTC
FEDORA-EPEL-2026-7671e4d4a3 has been pushed to the Fedora EPEL 10.2 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7671e4d4a3

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Fedora Update System 2026-08-23 00:25:58 UTC
FEDORA-EPEL-2026-da74b047d6 (libgit2_1.9-1.9.7-1.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 12 Fedora Update System 2026-08-23 00:40:53 UTC
FEDORA-EPEL-2026-a5f4b4222e (libgit2_1.9-1.9.7-1.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 13 Fedora Update System 2026-08-23 00:54:23 UTC
FEDORA-EPEL-2026-7671e4d4a3 (libgit2_1.9-1.9.7-1.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.