Executive brief
libgit2 is a widely-used library that provides Git functionality to applications. The vulnerability allows a malicious Git server to trigger an out-of-bounds memory read during the initial connection handshake, potentially crashing clients that interact with the server over HTTP, HTTPS, SSH, or the Git protocol. This could be weaponized for denial of service against applications built with vulnerable versions of libgit2.
Technical details
The vulnerability is a heap out-of-bounds read in the set_data function within src/libgit2/transports/smart_pkt.c. The code performs a fixed-size strncmp to detect the "object-format=" capability without first validating that the smart-protocol pkt-line capability buffer contains at least 14 bytes. A malicious Git server can send a specially crafted refs-advertisement packet that causes format_str to advance beyond the end of the pkt-line, leading to a memchr length calculation underflow and subsequent out-of-bounds memory access. The vulnerability is triggered during the first handshake packet exchange and affects all transport protocols (HTTP, HTTPS, SSH, Git). The fix, available in versions 1.8.6 and 1.9.5, adds a bounds check before the strncmp operation.
Affected products
- libgit2 libgit2 before 1.8.6 and before 1.9.5
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Fixed in versions 1.8.6 and 1.9.5