USN-8907-1: libgit2 vulnerability
Ubuntu warns libgit2 TLS IP certificate checks can enable a machine-in-the-middle attack.
Ubuntu Security Notice USN-8907-1 says libgit2 incorrectly verified IP address SubjectAltName entries during TLS certificate validation. A remote attacker with a CA-trusted certificate could use the flaw for a machine-in-the-middle attack and expose sensitive information. The notice does not name a CVE or report observed exploitation.