Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63381

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

A flaw was found in Libevent, an event notification library. A use-after-free vulnerability exists in the evbuffer_add_buffer_reference function when it processes an output buffer with a zero length. This can lead to a dangling pointer, which an attacker could exploit to cause memory corruption or crash the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libeventFix deferred
Red Hat Enterprise Linux 6libeventOut of support scope
Red Hat Enterprise Linux 6libevent2Out of support scope
Red Hat Enterprise Linux 7libeventFix deferred
Red Hat Enterprise Linux 8libeventFix deferred
Red Hat Enterprise Linux 9libeventAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Hardened Imageslibevent-main-2.1.12-19.1.hum1FixedRHSA-2026:6085329.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2520657libevent: Libevent: Memory corruption due to use-after-free

EPSS

Процентиль: 2%
0.00121
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

ubuntu
14 дней назад

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

nvd
14 дней назад

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

msrc
13 дней назад

Libevent: Dangling Pointer in `evbuffer_add_buffer_reference`

debian
14 дней назад

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...

CVSS3: 6.6
fstec
2 месяца назад

Уязвимость функции evbuffer_add_buffer_reference() библиотеки асинхронного уведомления событий Libevent, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00121
Низкий

6.6 Medium

CVSS3

Уязвимость CVE-2026-63381