Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a4d5162b52 2026-05-17 01:26:47.130155+00:00 -------------------------------------------------------------------------------- Name : libgit2_1.8 Product : Fedora 44 Version : 1.8.5 Release : 1.fc44 URL : https://libgit2.org/ Summary : C implementation of the Git core methods as a library with a solid API Description : libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language with bindings. -------------------------------------------------------------------------------- Update Information: Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Fabio Valentini - 1.8.5-1 - Update to version 1.8.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a4d5162b52' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bb6bb5d1e4 2026-05-17 01:05:24.299228+00:00 -------------------------------------------------------------------------------- Name : libgit2_1.8 Product : Fedora 42 Version : 1.8.5 Release : 1.fc42 URL : https://libgit2.org/ Summary : C implementation of the Git core methods as a library with a solid API Description : libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language with bindings. -------------------------------------------------------------------------------- Update Information: Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Fabio Valentini - 1.8.5-1 - Update to version 1.8.5 * Fri Jan 16 2026 Fedora Release Engineering - 1.8.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Thu Jul 24 2025 Fedora Release Engineering - 1.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun May 18 2025 Benjamin A. Beasley - 1.8.4-3 - Rebuilt for llhttp 9.3.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bb6bb5d1e4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7b1d032de7 2026-05-17 00:48:46.610610+00:00 -------------------------------------------------------------------------------- Name : libgit2_1.8 Product : Fedora 43 Version : 1.8.5 Release : 1.fc43 URL : https://libgit2.org/ Summary : C implementation of the Git core methods as a library with a solid API Description : libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language with bindings. -------------------------------------------------------------------------------- Update Information: Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Fabio Valentini - 1.8.5-1 - Update to version 1.8.5 * Fri Jan 16 2026 Fedora Release Engineering - 1.8.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7b1d032de7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-c0124f91bf 2026-02-08 01:08:54.528046+00:00 -------------------------------------------------------------------------------- Name : libgit2 Product : Fedora 43 Version : 1.9.2 Release : 1.fc43 URL : https://libgit2.org/ Summary : C implementation of the Git core methods as a library with a solid API Description : libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language with bindings. -------------------------------------------------------------------------------- Update Information: Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2 -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 27 2026 Josh Stone - 1.9.2-1 - Update to 1.9.2 * Fri Jan 16 2026 Fedora Release Engineering - 1.9.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c0124f91bf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-57ba9d6f85 2026-02-08 00:51:49.071229+00:00 -------------------------------------------------------------------------------- Name : libgit2 Product : Fedora 42 Version : 1.9.2 Release : 1.fc42 URL : https://libgit2.org/ Summary : C implementation of the Git core methods as a library with a solid API Description : libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language with bindings. -------------------------------------------------------------------------------- Update Information: Update to version 1.9.2. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2 -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 27 2026 Josh Stone - 1.9.2-1 - Update to 1.9.2 * Fri Jan 16 2026 Fedora Release Engineering - 1.9.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-57ba9d6f85' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been discovered in libgit2, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202411-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: libgit2: Multiple Vulnerabilities Date: November 06, 2024 Bugs: #891525, #923971 ID: 202411-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in libgit2, the worst of which could lead to arbitrary code execution. Background ========== libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language that supports C bindings. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ dev-libs/libgit2 < 1.7.2 > = 1.7.2 Description =========== Multiple vulnerabilities have been discovered in libgit2. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All libgit2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libgit2-1.7.2" References ========== [ 1 ] CVE-2023-22742 https://nvd.nist.gov/vuln/detail/CVE-2023-22742 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202411-05 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
* bsc#1219660 Cross-References: * CVE-2024-24577 . # Security update for libgit2 Announcement ID: SUSE-SU-2024:2619-1 Rating: important References: * bsc#1219660 Cross-References: * CVE-2024-24577 CVSS scores: * CVE-2024-24577 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2024-24577 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Development Tools Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libgit2 fixes the following issues: * CVE-2024-24577: Fixed arbitrary code execution due to heap corruption in git_index_add (bsc#1219660) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-2619=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2619=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-2619=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-2619=1 * SUSE Linux Enterprise High Performance ComputingLTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-2619=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-2619=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-2619=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-2619=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 * libgit2-debugsource-1.3.0-150400.3.9.1 * openSUSE Leap 15.4 (x86_64) * libgit2-1_3-32bit-debuginfo-1.3.0-150400.3.9.1 * libgit2-1_3-32bit-1.3.0-150400.3.9.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgit2-1_3-64bit-debuginfo-1.3.0-150400.3.9.1 * libgit2-1_3-64bit-1.3.0-150400.3.9.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 * libgit2-debugsource-1.3.0-150400.3.9.1 * openSUSE Leap 15.5 (x86_64) * libgit2-1_3-32bit-debuginfo-1.3.0-150400.3.9.1 * libgit2-1_3-32bit-1.3.0-150400.3.9.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 * libgit2-debugsource-1.3.0-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 * libgit2-debugsource-1.3.0-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 *libgit2-debugsource-1.3.0-150400.3.9.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 * libgit2-debugsource-1.3.0-150400.3.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 * libgit2-debugsource-1.3.0-150400.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libgit2-devel-1.3.0-150400.3.9.1 * libgit2-1_3-1.3.0-150400.3.9.1 * libgit2-1_3-debuginfo-1.3.0-150400.3.9.1 * libgit2-debugsource-1.3.0-150400.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24577.html * https://bugzilla.suse.com/show_bug.cgi?id=1219660 . Crucial libgit2 release for SUSE significantly boosts security by reducing risks of unauthorized code execution. Full patch information included.. SUSE Libgit2 Security Update, Arbitrary Code Execution, Security Patch, Linux Risk Management. . Severity: Important. LinuxSecurity.com Team
* bsc#1219660 Cross-References: * CVE-2024-24577 . # Security update for libgit2 Announcement ID: SUSE-SU-2024:2610-1 Rating: important References: * bsc#1219660 Cross-References: * CVE-2024-24577 CVSS scores: * CVE-2024-24577 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2024-24577 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 Module 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for libgit2 fixes the following issues: * CVE-2024-24577: Fixed arbitrary code execution due to heap corruption in git_index_add (bsc#1219660) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Server 4.3 Module 4.3 zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.3-2024-2610=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-2610=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-2610=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patchSUSE-SLE-Product-SLES-15-SP2-LTSS-2024-2610=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-2610=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-2610=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-2610=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-2610=1 ## Package List: * SUSE Manager Server 4.3 Module 4.3 (aarch64 ppc64le s390x x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-devel-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-devel-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-devel-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-devel-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-devel-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 * SUSE Linux EnterpriseServer for SAP Applications 15 SP3 (ppc64le x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-devel-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * libgit2-28-0.28.4-150200.3.9.1 * libgit2-devel-0.28.4-150200.3.9.1 * libgit2-28-debuginfo-0.28.4-150200.3.9.1 * libgit2-debugsource-0.28.4-150200.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24577.html * https://bugzilla.suse.com/show_bug.cgi?id=1219660 . Important notice about libgit2: a serious security flaw has been discovered that may enable arbitrary code execution. Immediate action is essential for all users and developers.. Security Patch, Libgit2 Update, SUSE Advisory, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.