Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63380

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha.

A flaw was found in Libevent, an event notification library. This vulnerability allows a local attacker to trigger a null pointer dereference during specific error handling within the evws_new_session function. By inducing an allocation or locking failure, an attacker can cause the application to crash, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libeventFix deferred
Red Hat Enterprise Linux 6libeventOut of support scope
Red Hat Enterprise Linux 6libevent2Out of support scope
Red Hat Enterprise Linux 7libeventFix deferred
Red Hat Enterprise Linux 8libeventFix deferred
Red Hat Enterprise Linux 9libeventAffected
Red Hat Hardened ImageslibeventNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2520656libevent: Libevent: Denial of Service via Null Pointer Dereference

EPSS

Процентиль: 2%
0.00113
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

ubuntu
14 дней назад

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha.

nvd
14 дней назад

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha.

debian
14 дней назад

Libevent is an event notification library. Prior to 2.2.2-alpha, libev ...

CVSS3: 4.7
fstec
2 месяца назад

Уязвимость функции evws_new_session() библиотеки асинхронного уведомления событий Libevent, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00113
Низкий

4.7 Medium

CVSS3