Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63384

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

A flaw was found in Libevent. An incorrect integer conversion in the evtag_unmarshal_header function allows a remote attacker to provide a specially crafted payload length. This can lead to a wrapped large allocation request, resulting in a denial of service (DoS) for the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libeventAffected
Red Hat Enterprise Linux 6libeventAffected
Red Hat Enterprise Linux 6libevent2Affected
Red Hat Enterprise Linux 7libeventAffected
Red Hat Enterprise Linux 8libeventAffected
Red Hat Enterprise Linux 9libeventAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected
Red Hat Hardened Imageslibevent-main-2.1.12-19.1.hum1FixedRHSA-2026:6085329.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2520658libevent: Libevent: Denial of Service via integer conversion error in `evtag_unmarshal_header`

EPSS

Процентиль: 31%
0.00384
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
14 дней назад

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

nvd
14 дней назад

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

msrc
13 дней назад

Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value.

debian
14 дней назад

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-a ...

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость функции evtag_unmarshal_header() библиотеки асинхронного уведомления событий Libevent, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 31%
0.00384
Низкий

7.5 High

CVSS3