Issued at: 2026-09-17
Updated at: 2026-09-17
Advisory content derived from Red Hat RHSA-2026:67910, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: libevent security update
Description
The libevent packages provide an abstract asynchronous event notification library.
Security Fix(es):
* libevent: Libevent: Denial of Service via malformed RPC data (CVE-2026-63383)
* libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption (CVE-2026-63387)
* libevent: Libevent: Memory corruption due to use-after-free (CVE-2026-63381)
* libevent: Libevent: Denial of Service via integer conversion error in `evtag_unmarshal_header` (CVE-2026-63384)
* libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling (CVE-2026-63382)
* libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling (CVE-2026-63388)
* libevent: Libevent: HTTP header handling bugs create risk of access control bypass. (CVE-2026-63385)
* libevent: Libevent: HTTP header smuggling allows authorization bypass or cache poisoning (CVE-2026-63379)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.