News

USN-8907-1: libgit2 flaw risks data exposure via TLS

Ubuntu fixes a libgit2 flaw in TLS certificate verification (CVE-2026-53583) on 24.04 and 26.04 LTS.

UptimeMag editorial team · 8 October 2026 · 1 min read

USN-8907-1: falla in libgit2, rischio esposizione di dati via TLS

Canonical published the USN-8907-1 advisory on 8 October 2026, fixing a vulnerability in libgit2, the C library implementing Git's core functions used by many build, CI/CD and automated deployment tools. It affects anyone running pipelines that clone repositories via HTTPS on Ubuntu 24.04 LTS and 26.04 LTS.

The issue

According to the official Ubuntu advisory, libgit2 incorrectly handled verification of the IP address-type SubjectAltName field during TLS certificate validation. A remote attacker in possession of a CA-trusted certificate could exploit the flaw to carry out a machine-in-the-middle attack, resulting in exposure of sensitive information transmitted during networked Git operations (clone, fetch, push via HTTPS).

The flaw is tracked as CVE-2026-53583.

Affected packages and fixed versions

Ubuntu release Package Fixed version
26.04 LTS (resolute) libgit2-1.9 1.9.1+ds-1ubuntu1.3
24.04 LTS (noble) libgit2-1.7 1.7.2+ds-1ubuntu3.3

How to update

According to Canonical, a standard system update automatically applies the fix:

sudo apt update && sudo apt upgrade

After updating, check the installed version with:

apt-cache policy libgit2-1.9

(or libgit2-1.7 on 24.04 LTS).

Ubuntu Pro users get ten years of security coverage on more than 25,000 packages in Main and Universe, free for up to 5 machines, as stated in the same advisory.

Source: official USN-8907-1 advisory, Ubuntu Security Notices, published 8 October 2026.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.