Home / mailingsPDF  

[SECURITY] [DSA 6493-1] libevent security update

Posted on 11 September 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6493-1 security@debian.org
https://www.debian.org/security/ Aron Xu
September 11, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libevent
CVE ID : CVE-2026-63379 CVE-2026-63381 CVE-2026-63382 CVE-2026-63383
CVE-2026-63384 CVE-2026-63385 CVE-2026-63387 CVE-2026-63388

Several vulnerabilities were discovered in libevent, an asynchronous event
notification library.

The HTTP implementation (evhttp) handled Transfer-Encoding and
Content-Length headers, chunked-encoding line terminators, header line
folding and chunked trailers too permissively, which could allow HTTP
request smuggling, header injection or access control bypass when a
libevent-based server or client is combined with an HTTP proxy.

Out-of-bounds memory accesses in the DNS (evdns), tagged RPC
(evtag/evrpc) and buffered socket (bufferevent) code, and a
use-after-free in evbuffer, could result in denial of service or
potentially the execution of arbitrary code when processing untrusted
input.

For the stable distribution (trixie), these problems have been fixed in
version 2.1.13-stable-1~deb13u1.

We recommend that you upgrade your libevent packages.

For the detailed security status of libevent please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libevent

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP