CVE-2026-63387

EUVD-2026-63508
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 33.61%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libevent_projectlibevent
𝑥
< 2.1.13
CNA
Debian logo
Debian Releases
Debian Product
Codename
libevent
bookworm
vulnerable
bookworm (security)
2.1.12-stable-8+deb12u1
fixed
forky
2.1.13-stable-1
fixed
sid
2.1.13-stable-1
fixed
trixie
vulnerable
trixie (security)
2.1.13-stable-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libevent
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
resolute
Fixed 2.1.12-stable-10ubuntu0.2
released
trusty
ignored
xenial
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libevent
RHEL 8
0:2.1.8-11.el8_10
fixed
RHEL 9
0:2.1.13-1.el9_8
fixed
libevent-devel
RHEL 8
0:2.1.8-11.el8_10
fixed
RHEL 9
0:2.1.13-1.el9_8
fixed
libevent-doc
RHEL 8
0:2.1.8-11.el8_10
fixed
RHEL 9
0:2.1.13-1.el9_8
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
libevent
Azure Linux 3.0
0:2.1.13-1.azl3
fixed
mysql
Azure Linux 3.0
0:8.0.46-2.azl3
fixed
ntp
Azure Linux 3.0
0:4.2.8p17-3.azl3
fixed