📖 ~4 min read • Source: Fedora update FEDORA-2026-bb6bb5d1e4
Upstream summary: Update to version 1.8.5.
Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5
Table of contents
Symptom & Impact
Nothing executes libgit2_1.8 on its own; its code runs inside whatever links against or imports it, so the exposed surface on a Fedora 42 host is the union of every process that has loaded it — web workers, cron jobs, mail handlers, backup agents. The package manager replaces the files on disk, but processes already running keep the old build mapped, and virtualenvs, vendored copies and container images each carry their own copy, so a host can report itself patched while still running vulnerable code. libgit2_1.8 is a library — code loaded by other programs rather than a daemon — so there is no unit to restart and systemctl status libgit2_1.8 will simply report no such unit; restart its consumers instead.
Environment & Reproduction
Reproduction targets Fedora 42. Confirm release and the installed package:
cat /etc/fedora-release
cat /etc/os-release
rpm -q libgit2_1.8
dnf info libgit2_1.8 | head -20
# Fedora 41+ ships dnf5 by default:
dnf5 info libgit2_1.8 | head -20
Exercise the workload that uses libgit2_1.8 while collecting:
sudo needs-restarting -u # --useronly: restrict to the invoking user's processes (useful on shared/app hosts)
sudo lsof -n +L1 # link count < 1 = file deleted but still open/mmap'd; this is the ground truth after an RPM replaces a .so (package: lsof)
sudo lsof -n +L1 2>/dev/null | awk 'NR>1 {print $1, $2}' | sort -u # condensed COMMAND + PID list of every process still running old code
sudo journalctl -xe --no-pager | tail -200
sudo tail -200 /var/log/dnf.log
sudo tail -200 /var/log/dnf5.log
sudo tail -200 /var/log/audit/audit.log
# For an evidence bundle with sosreport:
sudo sosreport --batch
Root Cause Analysis
Root cause is documented in Fedora update FEDORA-2026-bb6bb5d1e4. Fedora packagers shipped fixes in the corresponding libgit2_1.8 update for Fedora 42; running an outdated build leaves the host exposed to the failure modes described in the advisory. Correlate dnf history with system logs:
sudo dnf history | head
sudo dnf history list libgit2_1.8
sudo dnf history info <id>
sudo dnf5 history list # Fedora 41+
sudo ausearch -m AVC,USER_AVC -ts today | tail -100
cat /proc/sys/kernel/tainted # non-zero = tainted kernel / out-of-tree modules
Quick Triage
Run these on Fedora 42 to capture the current state of libgit2_1.8:
rpm -q libgit2_1.8 # installed NVR
rpm -V libgit2_1.8 # verify shipped files
sudo dnf check-update --security
sudo dnf updateinfo list cves
sudo dnf5 check-upgrade --security # Fedora 41+
systemctl --failed --no-pager
sudo firewall-cmd --list-all
getenforce && sestatus
dnf repoquery -l libgit2_1.8 2>/dev/null | grep -E '/lib/systemd/system/.*\.(service|socket|timer)$' # same check WITHOUT installing (EL7/Amazon Linux 2: yum install yum-utils, then: repoquery -l libgit2_1.8)
systemctl show --no-pager -p Type,RemainAfterExit <UNIT> # Type=oneshot (often paired with a .timer) means a one-shot job, NOT a daemon -- do not 'restart' it, let the timer fire
Step-by-Step Diagnosis
-
List failed systemd units.
systemctl --failed --no-pager -
Tail the journal for
libgit2_1.8and the system bus.sudo journalctl -xe -f --no-pager -
Inspect firewall posture.
sudo firewall-cmd --list-all-zones --permanent sudo nft list ruleset 2>/dev/null | head -50 -
Surface SELinux denials and author a local policy module if needed.
sudo ausearch -m AVC,USER_AVC -ts today sudo ausearch -m AVC -ts today | audit2allow -a -M /tmp/local-fix sudo semodule -i /tmp/local-fix.pp -
Verify
libgit2_1.8integrity and reinstall if anything is altered.sudo rpm -V libgit2_1.8 sudo dnf reinstall libgit2_1.8 sudo dnf5 reinstall libgit2_1.8 # Fedora 41+ -
Correlate findings with
/var/log/dnf.log,dnf history, and Fedora update FEDORA-2026-bb6bb5d1e4 to pin the change that introduced the regression.
Solution – Primary Fix
Before changing system packages on a btrfs-rooted Fedora 42 host take a cheap snapshot so a bad upgrade can be rolled back in seconds:
sudo btrfs subvolume snapshot / /.snapshots/pre-upgrade-$(date +%s)
sudo btrfs subvolume list / | tail
Apply the corrective dnf transaction referenced by Fedora update FEDORA-2026-bb6bb5d1e4, then reload affected systemd units:
sudo dnf -y makecache
sudo dnf -y upgrade --security # apply ALL security errata (recommended)
# Fedora 41+ ships dnf5 by default — equivalent commands:
sudo dnf5 upgrade --refresh
sudo dnf5 upgrade-minimal --security
# Or target a single package:
sudo dnf -y upgrade libgit2_1.8
sudo dnf5 upgrade libgit2_1.8 # Fedora 41+
sudo systemctl daemon-reload
# Unit name may differ from pkg name; check first:
sudo needs-restarting -s | sort -u # STEP 1: read the list before acting. dbus.service, systemd-logind.service and PID 1 must NOT be blind-restarted on a live host -- those mean 'reboot'
sudo systemctl daemon-reload # STEP 3: pick up any unit files the update rewrote
sudo systemctl restart <UNIT> && sudo systemctl is-active <UNIT> && sudo systemctl status --no-pager --full <UNIT> # single-unit path, with an immediate health check
systemctl --user list-units --type=service --no-pager # desktop/session and per-user services are a separate manager; restart them with: systemctl --user restart <UNIT>
rpm -q libgit2_1.8 # confirm new NVR
For kernel / glibc / systemd / openssl advisories a reboot is required (or kpatch where licensed):
sudo dnf needs-restarting -r # report whether reboot needed
sudo systemctl reboot # or: sudo shutdown -r now
# kpatch (where licensed) avoids reboot for many kernel CVEs:
sudo dnf install -y kpatch kpatch-dnf
sudo dnf kpatch auto # enable auto-patching
sudo kpatch list
Need help rolling this patch across a Fedora fleet? Our IT Solutions & Services team manages Fedora and CentOS Stream lifecycle with bodhi automation plus dnf-automatic. Get in touch for a free consultation.
Solution – Alternative Approaches
If the primary patch is not viable, choose from these:
-
Roll back the offending dnf transaction:
sudo dnf history list | head sudo dnf history info <id> sudo dnf history undo <id> sudo dnf5 history undo <id> # Fedora 41+ -
Version-lock the package so dnf cannot upgrade it:
sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add libgit2_1.8 sudo dnf versionlock list sudo dnf versionlock delete libgit2_1.8 # remove the lock -
Install an older NVR if a regression is suspected:
dnf --showduplicates list libgit2_1.8 | tac | head sudo dnf install -y --allowerasing libgit2_1.8-<older-NVR> -
Switch SELinux to permissive briefly to confirm policy is the cause, then re-enforce:
sudo setenforce 0 # reproduce, capture denials, author a custom module: sudo ausearch -m AVC -ts recent | audit2allow -a -M mylocal sudo semodule -i mylocal.pp sudo setenforce 1 -
Roll back via a btrfs snapshot taken before the upgrade (Fedora default root filesystem):
sudo btrfs subvolume list / # boot a rescue / live image, then promote the snapshot to /: sudo btrfs subvolume snapshot /.snapshots/pre-upgrade-<ts> /root-restored # update /etc/fstab and the bootloader to point at the restored subvolume. -
Where kpatch is available, apply kernel fixes without reboot:
sudo kpatch list sudo kpatch load /usr/lib/modules/$(uname -r)/extra/kpatch/*.ko
Verification & Acceptance Criteria
All of these should pass after the fix:
rpm -q libgit2_1.8 # expected fixed NVR
sudo dnf updateinfo list cves --installed # CVEs above no longer listed
sudo firewall-cmd --list-services
getenforce
sudo dnf needs-restarting -r
The conditions described in the advisory must no longer be reported for libgit2_1.8 across two consecutive runs.
Rollback Plan
Capture state before any change:
rpm -qa > /root/rpm-pre.txt
sudo dnf history list > /root/dnf-history-pre.txt
# Cheap btrfs snapshot of the root subvolume:
sudo btrfs subvolume snapshot / /.snapshots/pre-upgrade-$(date +%s)
To revert if the patch is bad:
sudo dnf history undo <id>
sudo dnf5 history undo <id> # Fedora 41+
# Or downgrade just the package:
sudo dnf install -y --allowerasing libgit2_1.8-<older-NVR>
sudo systemctl daemon-reload
# Or boot rescue and promote the btrfs snapshot back to /.
# Custom SELinux policy cleanup:
sudo semodule -r mylocal
Prevention & Hardening
Reduce the chance of this recurring on Fedora 42:
-
Enable automatic security patching with dnf-automatic:
sudo dnf install -y dnf-automatic sudo sed -i 's/^upgrade_type.*/upgrade_type = security/' /etc/dnf/automatic.conf sudo sed -i 's/^apply_updates.*/apply_updates = yes/' /etc/dnf/automatic.conf sudo systemctl enable --now dnf-automatic.timer sudo systemctl enable --now dnf-automatic-install.timer dnf updateinfo list cves --available -
Subscribe to fedora-announce and watch the Bodhi security updates feed for upstream changes.
-
Mirror through a local repo for controlled rollouts:
sudo dnf install -y dnf-utils createrepo_c sudo reposync --download-metadata --downloadcomps -p /srv/mirror --repoid=fedora sudo createrepo_c /srv/mirror/fedora -
Version-lock sensitive packages so they cannot be auto-upgraded:
sudo dnf install -y python3-dnf-plugin-versionlock sudo dnf versionlock add libgit2_1.8 -
Monitor file integrity with AIDE:
sudo dnf install -y aide sudo aide --init && sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz sudo aide --check -
Enable kpatch (where available) so kernel CVEs can be remediated without reboot:
sudo dnf install -y kpatch kpatch-dnf sudo dnf kpatch auto sudo kpatch list -
Keep SELinux in enforcing mode and review custom modules in
/etc/selinux/targeted/after every package upgrade. -
Apply CIS Fedora 42 Benchmark hardening and remove unused packages.
Related Errors & Cross-Refs
Issues that commonly surface alongside a libgit2_1.8 update: dnf lock contention, systemd unit ordering cycles, SELinux AVC bursts, firewalld zone drift, and kernel taint flags. Useful triage:
sudo dnf check
systemd-analyze critical-chain
sudo ausearch -m AVC -ts today | tail
sudo firewall-cmd --get-active-zones
cat /proc/sys/kernel/tainted
sudo dnf needs-restarting -r
View all fedora-42 tutorials on the Tutorials Hub →
Browse all common problems & solutions on the Tutorials Hub.
References & Further Reading
Primary reference: Fedora update FEDORA-2026-bb6bb5d1e4. Manual pages useful on Fedora 42:
man dnf
man dnf5
man dnf.conf
man systemctl
man journalctl
man firewall-cmd
man semanage
man audit2allow
man kpatch
man sosreport
man btrfs
Other resources: docs.fedoraproject.org, Bodhi update system, Red Hat CVE database, and per-package notes in /usr/share/doc/libgit2_1.8/ for components implicated in this advisory.