---
title: "CVE-2018-10887\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-10887?format=md
keywords: index, follow
---

# CVE-2018-10887

Publication date 10 July 2018

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.1 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2018-10887?format=md#impact-score)

Toggle side navigation

## Description

A flaw was found in libgit2 before version 0.27.3. It has been discovered
that an unexpected sign extension in git\_delta\_apply function in delta.c
file may lead to an integer overflow which in turn leads to an out of bound
read, allowing to read before the base object. An attacker may use this
flaw to leak memory addresses or cause a Denial of Service.

### From the Ubuntu Security Team

It was discovered that libgit2 mishandled specially crafted input. If a victim
were tricked into cloning a malicious repository or applying a malicious
patch, an attacker could cause libgit2 to leak sensitive information or crash.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libgit2 | 18.04 LTS bionic | Fixed 0.26.0+dfsg.1-1.1ubuntu0.2 |
| 17.10 artful | Ignored end of life |
| 16.04 LTS xenial | Fixed 0.24.1-2ubuntu0.2 |
| 14.04 LTS trusty | Fixed 0.19.0-2ubuntu0.4 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2018-10887?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| libgit2 | * Other:   [3f46190](https://github.com/libgit2/libgit2/commit/3f461902dc1072acb8b7607ee65d0a0458ffac2a) * Other:   [c157711](https://github.com/libgit2/libgit2/commit/c1577110467b701dcbcf9439ac225ea851b47d22) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.1 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.1 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10887)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-10887)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-10887)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-10887)

### Other references

* <https://bugzilla.redhat.com/show_bug.cgi?id=1598021>
* <https://github.com/libgit2/libgit2/releases/tag/v0.27.3>
* <https://www.cve.org/CVERecord?id=CVE-2018-10887>
