UbuntuUpdates.org

Package "libevent-2.1-7t64"

Name: libevent-2.1-7t64

Description:

Asynchronous event notification library

Latest version: 2.1.12-stable-9ubuntu2.1
Release: noble (24.04)
Level: updates
Repository: main
Head package: libevent
Homepage: https://libevent.org/

Links


Download "libevent-2.1-7t64"


Other versions of "libevent-2.1-7t64" in Noble

Repository Area Version
base main 2.1.12-stable-9ubuntu2
security main 2.1.12-stable-9ubuntu2.1

Changelog

Version: 2.1.12-stable-9ubuntu2.1 2026-09-01 18:07:41 UTC

libevent (2.1.12-stable-9ubuntu2.1) noble-security; urgency=medium

  * SECURITY UPDATE: dangling pointer in buffer reference handling
    - debian/patches/CVE-2026-63381.patch: reset empty output buffer
      pointers and add regression coverage in buffer.c and
      test/regress_buffer.c.
    - CVE-2026-63381
  * SECURITY UPDATE: HTTP request smuggling in request body framing
    - debian/patches/CVE-2026-63382_1.patch: require strict CRLF chunk
      delimiters in http.c.
    - debian/patches/CVE-2026-63382_2.patch: validate transfer encodings
      and add tests in http-internal.h, http.c, and test/regress_http.c.
    - CVE-2026-63382
  * SECURITY UPDATE: out-of-bounds read during RPC tag decoding
    - debian/patches/CVE-2026-63383.patch: bound tag decoding to contiguous
      buffer data in event_tagging.c.
    - CVE-2026-63383
  * SECURITY UPDATE: integer overflow during RPC payload length decoding
    - debian/patches/CVE-2026-63384.patch: reject oversized RPC payload
      lengths in event_tagging.c and document the limit in
      include/event2/tag.h.
    - CVE-2026-63384
  * SECURITY UPDATE: HTTP header injection during folded header handling
    - debian/patches/CVE-2026-63385.patch: reject CR and LF in HTTP header
      values and update tests in http.c and test/regress_http.c.
    - CVE-2026-63385

 -- Shafayat Hossain Majumder Fri, 28 Aug 2026 16:44:18 -0400

CVE-2026-63381 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere
CVE-2026-63382 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra
CVE-2026-63383 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c
CVE-2026-63384 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta
CVE-2026-63385 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int



About   -   Send Feedback to @ubuntu_updates