Skip to content

[AUTOPATCHER-CORE] Upgrade libgit2 to 1.8.7 for CVE-2026-53586, CVE-2026-53585, CVE-2026-53587, CVE-2026-53583, CVE-2026-53584 - #18547

Draft
azurelinux-ci-jwt-app[bot] wants to merge 1 commit into
fasttrack/3.0from
cblmargh/libgit2-upgrade-to-1.8.7-fasttrack/3.0
Draft

[AUTOPATCHER-CORE] Upgrade libgit2 to 1.8.7 for CVE-2026-53586, CVE-2026-53585, CVE-2026-53587, CVE-2026-53583, CVE-2026-53584#18547
azurelinux-ci-jwt-app[bot] wants to merge 1 commit into
fasttrack/3.0from
cblmargh/libgit2-upgrade-to-1.8.7-fasttrack/3.0

Conversation

@azurelinux-ci-jwt-app

@azurelinux-ci-jwt-app azurelinux-ci-jwt-app Bot commented Aug 21, 2026

Copy link
Copy Markdown

[AUTOPATCHER-CORE] Upgrade libgit2 to 1.8.7 for CVE-2026-53586, CVE-2026-53585, CVE-2026-53587, CVE-2026-53583, CVE-2026-53584
Upgrade pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1187003&view=results

The upgrade actually has one issue. The 1.8.7 libgit2 has moved to llhttp as http is no longer maintained but Azure Linux doesn't have llhttp in core repo, only extended has it. Further, if we use bundled llhttp, then there is risk of cves because bundled version may not fix all the cves always. We will verify once if the bundled version is regular upgraded to address cves.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@microsoft-github-policy-service microsoft-github-policy-service Bot added Packaging fasttrack/3.0 PRs Destined for Azure Linux 3.0 labels Aug 21, 2026
@kgodara912
kgodara912 marked this pull request as draft August 21, 2026 14:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants