Fedora 44 libgit2 and rust-libgit2-sys Security Updates Address Multiple CVEs

Fedora 44 libgit2 and rust-libgit2-sys Security Updates Address Multiple CVEs

First seen 27 Jul 2026, 08:31 UTC Linuxsecurity 84% similarity 57.9

Article Content

Browse articles
ThreatCluster

On July 27, 2026, Fedora released updates for libgit2 and rust-libgit2-sys to address multiple security vulnerabilities, including CVE-2026-53583 through CVE-2026-53587. These updates are critical for users of Fedora 44, as they mitigate risks associated with the use of the libgit2 library, a widely utilized Git core methods implementation. The vulnerabilities could potentially lead to privilege escalation and system-wide damage if exploited. Users are advised to update to libgit2 version 1.9.6 and rust-libgit2-sys version 0.18.7 to ensure their systems are secure. The Fedora packages are not affected by a specific vulnerability (GHSA-wfx7-g85r-q6vw) due to their linking practices. The updates were made available on the same day as the announcement.

Key Points: • Fedora 44 updates libgit2 and rust-libgit2-sys to fix multiple CVEs. • Vulnerabilities include CVE-2026-53583 to CVE-2026-53587. • Users are urged to upgrade to versions 1.9.6 and 0.18.7 immediately.

ThreatCluster AI

Timeline

2026-07-23
libgit2 version 1.9.6 released
Fedora updated libgit2 to version 1.9.6 to address several security vulnerabilities.
Linuxsecurity
2026-07-23
rust-libgit2-sys version 0.18.7 released
Fedora updated rust-libgit2-sys to version 0.18.7, fixing related security issues.
Linuxsecurity
2026-07-27
Security updates announced
Fedora announced the availability of critical security updates for libgit2 and rust-libgit2-sys.
Linuxsecurity

Community

Browse all →