Home / mailings [USN-8710-1] libevent vulnerabilities
Posted on 01 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8710-1
September 01, 2026
libevent vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in libevent.
Software Description:
- libevent: Event notification library
Details:
Alexis Challande discovered that libevent incorrectly handled certain
empty output buffers. An attacker could possibly use this issue to
trigger a use-after-free, resulting in a denial of service or arbitrary
code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-63381)
Rajat Raghav discovered that libevent incorrectly handled certain HTTP
requests. An attacker could possibly use this issue to desynchronize
HTTP request boundaries, resulting in HTTP request smuggling.
(CVE-2026-63382)
Qiu Sihao discovered that libevent incorrectly handled certain malformed
tagged RPC data. An attacker could possibly use this issue to trigger an
out-of-bounds read, resulting in a denial of service. (CVE-2026-63383)
Qiu Sihao discovered that libevent incorrectly handled certain large
payload lengths in tagged RPC data. An attacker could possibly use this
issue to consume excessive system resources, resulting in a denial of
service. (CVE-2026-63384)
Asaf Meizner discovered that libevent incorrectly handled certain HTTP
URIs and header values. An attacker could possibly use this issue to
cause HTTP messages to be interpreted inconsistently, resulting in
security restrictions being bypassed. (CVE-2026-63385)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libevent-2.1-7t64 2.1.12-stable-10ubuntu0.1
libevent-core-2.1-7t64 2.1.12-stable-10ubuntu0.1
libevent-dev 2.1.12-stable-10ubuntu0.1
libevent-extra-2.1-7t64 2.1.12-stable-10ubuntu0.1
Ubuntu 24.04 LTS
libevent-2.1-7t64 2.1.12-stable-9ubuntu2.1
libevent-core-2.1-7t64 2.1.12-stable-9ubuntu2.1
libevent-dev 2.1.12-stable-9ubuntu2.1
libevent-extra-2.1-7t64 2.1.12-stable-9ubuntu2.1
Ubuntu 22.04 LTS
libevent-2.1-7 2.1.12-stable-1ubuntu0.1
libevent-core-2.1-7 2.1.12-stable-1ubuntu0.1
libevent-dev 2.1.12-stable-1ubuntu0.1
libevent-extra-2.1-7 2.1.12-stable-1ubuntu0.1
Ubuntu 20.04 LTS
libevent-2.1-7 2.1.11-stable-1ubuntu0.1~esm1
Available with Ubuntu Pro
libevent-core-2.1-7 2.1.11-stable-1ubuntu0.1~esm1
Available with Ubuntu Pro
libevent-dev 2.1.11-stable-1ubuntu0.1~esm1
Available with Ubuntu Pro
libevent-extra-2.1-7 2.1.11-stable-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libevent-2.1-6 2.1.8-stable-4ubuntu0.1~esm1
Available with Ubuntu Pro
libevent-core-2.1-6 2.1.8-stable-4ubuntu0.1~esm1
Available with Ubuntu Pro
libevent-dev 2.1.8-stable-4ubuntu0.1~esm1
Available with Ubuntu Pro
libevent-extra-2.1-6 2.1.8-stable-4ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libevent-2.0-5 2.0.21-stable-2ubuntu0.16.04.1+esm1
Available with Ubuntu Pro
libevent-core-2.0-5 2.0.21-stable-2ubuntu0.16.04.1+esm1
Available with Ubuntu Pro
libevent-dev 2.0.21-stable-2ubuntu0.16.04.1+esm1
Available with Ubuntu Pro
libevent-extra-2.0-5 2.0.21-stable-2ubuntu0.16.04.1+esm1
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libevent-2.0-5 2.0.21-stable-1ubuntu1.14.04.2+esm1
Available with Ubuntu Pro
libevent-core-2.0-5 2.0.21-stable-1ubuntu1.14.04.2+esm1
Available with Ubuntu Pro
libevent-dev 2.0.21-stable-1ubuntu1.14.04.2+esm1
Available with Ubuntu Pro
libevent-extra-2.0-5 2.0.21-stable-1ubuntu1.14.04.2+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8710-1
CVE-2026-63381, CVE-2026-63382, CVE-2026-63383, CVE-2026-63384,
CVE-2026-63385
Package Information:
https://launchpad.net/ubuntu/+source/libevent/2.1.12-stable-10ubuntu0.1
https://launchpad.net/ubuntu/+source/libevent/2.1.12-stable-9ubuntu2.1
https://launchpad.net/ubuntu/+source/libevent/2.1.12-stable-1ubuntu0.1
--===============1069511433390482395==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
