[ALSA-2026:67910] Important: libevent security update
Type:
security
Severity:
important
Release date:
2026-09-17
Description:
The libevent packages provide an abstract asynchronous event notification library. Security Fix(es): * libevent: Libevent: Denial of Service via malformed RPC data (CVE-2026-63383) * libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption (CVE-2026-63387) * libevent: Libevent: Memory corruption due to use-after-free (CVE-2026-63381) * libevent: Libevent: Denial of Service via integer conversion error in `evtag_unmarshal_header` (CVE-2026-63384) * libevent ev[http:](http:) Multiple HTTP Parser Bugs Enable Request Smuggling (CVE-2026-63382) * libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling (CVE-2026-63388) * libevent: Libevent: HTTP header handling bugs create risk of access control bypass. (CVE-2026-63385) * libevent: Libevent: HTTP header smuggling allows authorization bypass or cache poisoning (CVE-2026-63379) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libevent-devel-2.1.13-1.el9_8.aarch64.rpm 4362c30284d40f38197f19d53e8e305f06c7e35329998200333403441e24fe39
aarch64 libevent-2.1.13-1.el9_8.aarch64.rpm abf170fac73bb5c674fb37448026a9adb6c7ac7e2dcd7218c10edc2023be8fa0
i686 libevent-2.1.13-1.el9_8.i686.rpm 5006271ef39ff121a0201066c308d024734b06830b00dc1e689b1f7fc7232adb
i686 libevent-devel-2.1.13-1.el9_8.i686.rpm ce0adbfc1b5836c990de649ba287da83feb1fe2adffad88e14837e7e94b44a99
noarch libevent-doc-2.1.13-1.el9_8.noarch.rpm 56b63bfc369e5e5d2c14e2056b0e942db4cea5e72e17fb9875b72dfb75749de6
ppc64le libevent-2.1.13-1.el9_8.ppc64le.rpm 74344559ffecfb9957374abc968e3efd5558ed78690f64cc5e59a772f1805119
ppc64le libevent-devel-2.1.13-1.el9_8.ppc64le.rpm fa5126d28c2990d298e5c3f5db9ac6e79fc38835f3a79949f28fc0b59203df67
s390x libevent-2.1.13-1.el9_8.s390x.rpm 457f987e2134ea27bd9786e5480a5492bc77a8e1847dc5d8b5efc7b404f5491e
s390x libevent-devel-2.1.13-1.el9_8.s390x.rpm b84546ccd2b0c68188c4a5e1c9484a6950568815d1237cb8ef908577f8a1310b
x86_64 libevent-2.1.13-1.el9_8.x86_64.rpm 09dc28d18a416255c059605f60ef03f2196f31d8137caa9ad517040f6f789f1b
x86_64 libevent-devel-2.1.13-1.el9_8.x86_64.rpm 7a3933ee380540b1211bffc3b9e4d6fc7581ae1e31a8c060b2df91e8c1179c86
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.