CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8710-1: libevent vulnerabilities

unknownCVE-2026-63381CVE-2026-63382CVE-2026-63383CVE-2026-63384CVE-2026-63385
Alexis Challande discovered that libevent incorrectly handled certain empty output buffers. An attacker could possibly use this issue to trigger a use-after-free, resulting in a denial of service or arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63381) Rajat Raghav discovered that libevent incorrectly handled certain HTTP requests. An attacker could possibly use this issue to desynchronize HTTP request boundaries, resulting in HTTP request smuggling. (CVE-2026-63382) Qiu Sihao discovered that libevent incorrectly handled certain malformed tagged RPC data. An attacker could possibly use this issue to trigger an out-of-bounds read, resulting in a denial of service. (CVE-2026-63383) Qiu Sihao discovered that libevent incorrectly handled certain large payload lengths in tagged RPC data. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-63384) Asaf Meizner discovered that libevent incorrectly handled certain HTTP URIs and header values. An attacker could possibly use this issue to cause HTTP messages to be interpreted inconsistently, resulting in security restrictions being bypassed. (CVE-2026-63385)

CSIRTS triage

vendor: libeventproduct: libeventMemory corruptionDenial of serviceRemote code executionOtheraffected: Affected on Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, 26.04 LTS
What
libevent has multiple vulnerabilities including use-after-free in empty output buffer handling, HTTP request smuggling, and out-of-bounds reads in RPC data parsing.
Who is affected
Systems running libevent on Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS.
Urgency
High; use-after-free can cause denial of service or arbitrary code execution, and HTTP request smuggling allows request desynchronization.
Action
Apply Ubuntu security updates USN-8710-1 to patch CVE-2026-63381, CVE-2026-63382, CVE-2026-63383, CVE-2026-63384, and CVE-2026-63385.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch libevent

Get an email when a new libevent advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-09-01
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8710-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-63381coverage & exploitation statusNVD · CVE.org
CVE-2026-63382coverage & exploitation statusNVD · CVE.org
CVE-2026-63383coverage & exploitation statusNVD · CVE.org
CVE-2026-63384coverage & exploitation statusNVD · CVE.org
CVE-2026-63385coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices