CVE-2026-63388

Source
https://cve.org/CVERecord?id=CVE-2026-63388
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63388.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63388
Aliases
  • GHSA-cvq5-vrvr-j338
Downstream
Published
2026-08-20T17:44:18.435Z
Modified
2026-08-22T16:16:23.047010Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept
Details

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in buffereventsock.c when buffereventsocketsetconnaddress copies a kernel-supplied AFUNIX peer address into buffereventprivate.connaddress. Release builds compiled with NDEBUG disable the EVUTILASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AFUNIX listener can overwrite the adjacent dnsrequest pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-617",
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63388.json"
}
References

Affected packages

Git / github.com/libevent/libevent

Affected ranges

Type
GIT
Repo
https://github.com/libevent/libevent
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.1.13"
        },
        {
            "introduced": "2.2.0-alpha"
        },
        {
            "fixed": "2.2.2-alpha"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

release-1.*
release-1.1b
release-2.*
release-2.0.1-alpha
release-2.0.10-stable
release-2.0.3-alpha
release-2.0.4-alpha
release-2.0.5-beta
release-2.0.6-rc
release-2.0.7-rc
release-2.0.8-rc
release-2.0.9-rc
release-2.1.1-alpha
release-2.1.10-stable
release-2.1.11-stable
release-2.1.12-stable
release-2.1.2-alpha
release-2.1.3-alpha
release-2.1.4-alpha
release-2.1.5-beta
release-2.1.6-beta
release-2.1.7-rc
release-2.1.8-stable
release-2.1.9-beta
release-2.2.1-alpha

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63388.json"
vanir_signatures
[
    {
        "target": {
            "file": "bufferevent_sock.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
        "id": "CVE-2026-63388-020d511d",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "101819609957744269698121801527631572781",
                "266411754998326005194547333746409271096",
                "215423157039678547561540407747446022666",
                "40020089239711087926668970476583324813",
                "300275853617353464170734771672508051372",
                "67971310237992188444143576791278135055",
                "266086422330318696521687348815895819917",
                "124484835582547956811906048466030625353",
                "273333122966952922262090303543566282444",
                "269456776861241227892815659694841584047",
                "23209942639021563305301349571508664348",
                "166240550890098995901313235965252251927",
                "101649725304558230856853114336241928173",
                "95518984606465138982335662606763146773",
                "316945380325628039743563743457862476147",
                "223882309331775775235956358656177270671",
                "318849267121895470368367781863355733001",
                "260206147218973727343780190017513919827"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "bufferevent_socket_set_conn_address_",
            "file": "bufferevent_sock.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
        "id": "CVE-2026-63388-090bab49",
        "signature_version": "v1",
        "digest": {
            "length": 209.0,
            "function_hash": "167754556514829958597606100595652938473"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "http_check_transfer_encoding_test",
            "file": "test/regress_http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/df3ecad3a040fd6d4fad4287defe113395de6fd7",
        "id": "CVE-2026-63388-09212634",
        "signature_version": "v1",
        "digest": {
            "length": 554.0,
            "function_hash": "159443554126248192493229143747497657830"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
        "id": "CVE-2026-63388-1b906a58",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "290195691034667613405197220907988912358",
                "38370868899952103588205489961376735756",
                "190256165863275220022616874542587848866",
                "232755479056248490437072749186447050864"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "bufferevent_connect_getaddrinfo_cb",
            "file": "bufferevent_sock.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
        "id": "CVE-2026-63388-2f639853",
        "signature_version": "v1",
        "digest": {
            "length": 754.0,
            "function_hash": "280743327974420631042884747181096349617"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "bufferevent_socket_set_conn_address_",
            "file": "bufferevent_sock.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
        "id": "CVE-2026-63388-4a7815f8",
        "signature_version": "v1",
        "digest": {
            "length": 209.0,
            "function_hash": "167754556514829958597606100595652938473"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "bufferevent_connect_getaddrinfo_cb",
            "file": "bufferevent_sock.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
        "id": "CVE-2026-63388-80691ef3",
        "signature_version": "v1",
        "digest": {
            "length": 754.0,
            "function_hash": "280743327974420631042884747181096349617"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "bufferevent_sock.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
        "id": "CVE-2026-63388-82413a0d",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "101819609957744269698121801527631572781",
                "266411754998326005194547333746409271096",
                "215423157039678547561540407747446022666",
                "40020089239711087926668970476583324813",
                "300275853617353464170734771672508051372",
                "67971310237992188444143576791278135055",
                "266086422330318696521687348815895819917",
                "124484835582547956811906048466030625353",
                "273333122966952922262090303543566282444",
                "269456776861241227892815659694841584047",
                "23209942639021563305301349571508664348",
                "166240550890098995901313235965252251927",
                "101649725304558230856853114336241928173",
                "95518984606465138982335662606763146773",
                "316945380325628039743563743457862476147",
                "223882309331775775235956358656177270671",
                "318849267121895470368367781863355733001",
                "260206147218973727343780190017513919827"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "evhttp_get_request_connection",
            "file": "http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
        "id": "CVE-2026-63388-85d6a1c8",
        "signature_version": "v1",
        "digest": {
            "length": 1797.0,
            "function_hash": "282485064830107023485238431842831355765"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
        "id": "CVE-2026-63388-900bc271",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "290195691034667613405197220907988912358",
                "38370868899952103588205489961376735756",
                "190256165863275220022616874542587848866",
                "232755479056248490437072749186447050864"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "test/regress_http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/df3ecad3a040fd6d4fad4287defe113395de6fd7",
        "id": "CVE-2026-63388-923050c6",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "270762094980121927552802584929566056086",
                "37564212311334647331345684303177453724",
                "168570413533780985513641597969239978857"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "test/regress_http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/79ddfb460847999b807cba76d04e73891f29c6ee",
        "id": "CVE-2026-63388-979e5bed",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "270762094980121927552802584929566056086",
                "37564212311334647331345684303177453724",
                "168570413533780985513641597969239978857"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "bufferevent-internal.h"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
        "id": "CVE-2026-63388-b1c9ae03",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "44309742689991378301779096633227149655",
                "43198124566305926637904622364365956869",
                "195046203857076418857261348719827040892",
                "171154218049367300199286677976667160383",
                "104591516658529530808389725282113432610",
                "245318260599149105139158161214958222220",
                "162054502596379093864094100138052079297",
                "306362243852346808614861351024610289507",
                "84772691122130129346267929892591199670",
                "106475485927887069795169520578428818879",
                "760843948176936763736614088550450550",
                "335271424882635951560873778971558878032",
                "175621808709427662963164976335237869217",
                "145714137223063175349171764531678955926",
                "158727773730644317290685446922040039169"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "bufferevent-internal.h"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
        "id": "CVE-2026-63388-db5de430",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "44309742689991378301779096633227149655",
                "43198124566305926637904622364365956869",
                "195046203857076418857261348719827040892",
                "171154218049367300199286677976667160383",
                "104591516658529530808389725282113432610",
                "245318260599149105139158161214958222220",
                "162054502596379093864094100138052079297",
                "306362243852346808614861351024610289507",
                "84772691122130129346267929892591199670",
                "106475485927887069795169520578428818879",
                "760843948176936763736614088550450550",
                "335271424882635951560873778971558878032",
                "175621808709427662963164976335237869217",
                "145714137223063175349171764531678955926",
                "158727773730644317290685446922040039169"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "evhttp_get_request_connection",
            "file": "http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
        "id": "CVE-2026-63388-eb04d077",
        "signature_version": "v1",
        "digest": {
            "length": 1418.0,
            "function_hash": "229824989913640716274657054148484746048"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "http_check_transfer_encoding_test",
            "file": "test/regress_http.c"
        },
        "deprecated": false,
        "source": "https://github.com/libevent/libevent/commit/79ddfb460847999b807cba76d04e73891f29c6ee",
        "id": "CVE-2026-63388-ebc5ab94",
        "signature_version": "v1",
        "digest": {
            "length": 554.0,
            "function_hash": "159443554126248192493229143747497657830"
        },
        "signature_type": "Function"
    }
]
vanir_signatures_modified
"2026-08-22T16:16:23Z"