[ALSA-2026:67909] Important: libevent security update
Type:
security
Severity:
important
Release date:
2026-09-17
Description:
The libevent packages provide an abstract asynchronous event notification library. Security Fix(es): * libevent: Libevent: Denial of Service via malformed RPC data (CVE-2026-63383) * libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption (CVE-2026-63387) * libevent: Libevent: Memory corruption due to use-after-free (CVE-2026-63381) * libevent: Libevent: Denial of Service via integer conversion error in `evtag_unmarshal_header` (CVE-2026-63384) * libevent ev[http:](http:) Multiple HTTP Parser Bugs Enable Request Smuggling (CVE-2026-63382) * libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling (CVE-2026-63388) * libevent: Libevent: HTTP header handling bugs create risk of access control bypass. (CVE-2026-63385) * libevent: Libevent: HTTP header smuggling allows authorization bypass or cache poisoning (CVE-2026-63379) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libevent-2.1.13-1.el10_2.aarch64.rpm 22ef3aca098d62bce9e86ee8759a96c95f60a7a2ed61a81b9c156db3bb9d585b
aarch64 libevent-devel-2.1.13-1.el10_2.aarch64.rpm 5918ff49b4a7fa05bfcf2069ba4e4067b7cdfe09999bf0483a88096fdcaea7be
noarch libevent-doc-2.1.13-1.el10_2.noarch.rpm 8f97e5ea7d9bd2f38f36ae5c546a1143c2438ea22193be05cfb08d3a9e3159b3
ppc64le libevent-2.1.13-1.el10_2.ppc64le.rpm 1416089bdbff84029aad8c0e2791a83816fd1e52b03b7104a7d00436d21d70f1
ppc64le libevent-devel-2.1.13-1.el10_2.ppc64le.rpm d009564e64e138c5114c59b2b5ad90faabe88d3b8e59670866051a9a836cf155
s390x libevent-2.1.13-1.el10_2.s390x.rpm 83f5a549b6f7b8c9c1a5c2285ab57a0b3b2bf6ff79b0cc768a5cd508d9b6ceab
s390x libevent-devel-2.1.13-1.el10_2.s390x.rpm e30591f312cdd74411751bcff717b2225092c5006ee6ce1fc21624353f00daa4
x86_64 libevent-devel-2.1.13-1.el10_2.x86_64.rpm 07cc35369cbb21b033ba25e20dafeb96034d7e48bca715eca48db7eda751e07d
x86_64 libevent-2.1.13-1.el10_2.x86_64.rpm 9c8ba5e41048330a3085ac3c6ebbbe86a6fb9a4b5f4b8407cf1215263ce32f5f
x86_64_v2 libevent-devel-2.1.13-1.el10_2.x86_64_v2.rpm 47c956fdc81f080bfb31e24d4e37e925f402ba4c111bf315ad287d868542275c
x86_64_v2 libevent-2.1.13-1.el10_2.x86_64_v2.rpm d53b8fbfa85ac5c4d7cffcd711c38a594a648f1cd44a415caaa18f2d63ac15c4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.