Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in buffereventsock.c when buffereventsocketsetconnaddress copies a kernel-supplied AFUNIX peer address into buffereventprivate.connaddress. Release builds compiled with NDEBUG disable the EVUTILASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AFUNIX listener can overwrite the adjacent dnsrequest pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-617",
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63388.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.1.13"
},
{
"introduced": "2.2.0-alpha"
},
{
"fixed": "2.2.2-alpha"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63388.json"
[
{
"target": {
"file": "bufferevent_sock.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
"id": "CVE-2026-63388-020d511d",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"101819609957744269698121801527631572781",
"266411754998326005194547333746409271096",
"215423157039678547561540407747446022666",
"40020089239711087926668970476583324813",
"300275853617353464170734771672508051372",
"67971310237992188444143576791278135055",
"266086422330318696521687348815895819917",
"124484835582547956811906048466030625353",
"273333122966952922262090303543566282444",
"269456776861241227892815659694841584047",
"23209942639021563305301349571508664348",
"166240550890098995901313235965252251927",
"101649725304558230856853114336241928173",
"95518984606465138982335662606763146773",
"316945380325628039743563743457862476147",
"223882309331775775235956358656177270671",
"318849267121895470368367781863355733001",
"260206147218973727343780190017513919827"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "bufferevent_socket_set_conn_address_",
"file": "bufferevent_sock.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
"id": "CVE-2026-63388-090bab49",
"signature_version": "v1",
"digest": {
"length": 209.0,
"function_hash": "167754556514829958597606100595652938473"
},
"signature_type": "Function"
},
{
"target": {
"function": "http_check_transfer_encoding_test",
"file": "test/regress_http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/df3ecad3a040fd6d4fad4287defe113395de6fd7",
"id": "CVE-2026-63388-09212634",
"signature_version": "v1",
"digest": {
"length": 554.0,
"function_hash": "159443554126248192493229143747497657830"
},
"signature_type": "Function"
},
{
"target": {
"file": "http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
"id": "CVE-2026-63388-1b906a58",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"290195691034667613405197220907988912358",
"38370868899952103588205489961376735756",
"190256165863275220022616874542587848866",
"232755479056248490437072749186447050864"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "bufferevent_connect_getaddrinfo_cb",
"file": "bufferevent_sock.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
"id": "CVE-2026-63388-2f639853",
"signature_version": "v1",
"digest": {
"length": 754.0,
"function_hash": "280743327974420631042884747181096349617"
},
"signature_type": "Function"
},
{
"target": {
"function": "bufferevent_socket_set_conn_address_",
"file": "bufferevent_sock.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
"id": "CVE-2026-63388-4a7815f8",
"signature_version": "v1",
"digest": {
"length": 209.0,
"function_hash": "167754556514829958597606100595652938473"
},
"signature_type": "Function"
},
{
"target": {
"function": "bufferevent_connect_getaddrinfo_cb",
"file": "bufferevent_sock.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
"id": "CVE-2026-63388-80691ef3",
"signature_version": "v1",
"digest": {
"length": 754.0,
"function_hash": "280743327974420631042884747181096349617"
},
"signature_type": "Function"
},
{
"target": {
"file": "bufferevent_sock.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
"id": "CVE-2026-63388-82413a0d",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"101819609957744269698121801527631572781",
"266411754998326005194547333746409271096",
"215423157039678547561540407747446022666",
"40020089239711087926668970476583324813",
"300275853617353464170734771672508051372",
"67971310237992188444143576791278135055",
"266086422330318696521687348815895819917",
"124484835582547956811906048466030625353",
"273333122966952922262090303543566282444",
"269456776861241227892815659694841584047",
"23209942639021563305301349571508664348",
"166240550890098995901313235965252251927",
"101649725304558230856853114336241928173",
"95518984606465138982335662606763146773",
"316945380325628039743563743457862476147",
"223882309331775775235956358656177270671",
"318849267121895470368367781863355733001",
"260206147218973727343780190017513919827"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "evhttp_get_request_connection",
"file": "http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
"id": "CVE-2026-63388-85d6a1c8",
"signature_version": "v1",
"digest": {
"length": 1797.0,
"function_hash": "282485064830107023485238431842831355765"
},
"signature_type": "Function"
},
{
"target": {
"file": "http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
"id": "CVE-2026-63388-900bc271",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"290195691034667613405197220907988912358",
"38370868899952103588205489961376735756",
"190256165863275220022616874542587848866",
"232755479056248490437072749186447050864"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "test/regress_http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/df3ecad3a040fd6d4fad4287defe113395de6fd7",
"id": "CVE-2026-63388-923050c6",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"270762094980121927552802584929566056086",
"37564212311334647331345684303177453724",
"168570413533780985513641597969239978857"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "test/regress_http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/79ddfb460847999b807cba76d04e73891f29c6ee",
"id": "CVE-2026-63388-979e5bed",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"270762094980121927552802584929566056086",
"37564212311334647331345684303177453724",
"168570413533780985513641597969239978857"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "bufferevent-internal.h"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9",
"id": "CVE-2026-63388-b1c9ae03",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"44309742689991378301779096633227149655",
"43198124566305926637904622364365956869",
"195046203857076418857261348719827040892",
"171154218049367300199286677976667160383",
"104591516658529530808389725282113432610",
"245318260599149105139158161214958222220",
"162054502596379093864094100138052079297",
"306362243852346808614861351024610289507",
"84772691122130129346267929892591199670",
"106475485927887069795169520578428818879",
"760843948176936763736614088550450550",
"335271424882635951560873778971558878032",
"175621808709427662963164976335237869217",
"145714137223063175349171764531678955926",
"158727773730644317290685446922040039169"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "bufferevent-internal.h"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
"id": "CVE-2026-63388-db5de430",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"44309742689991378301779096633227149655",
"43198124566305926637904622364365956869",
"195046203857076418857261348719827040892",
"171154218049367300199286677976667160383",
"104591516658529530808389725282113432610",
"245318260599149105139158161214958222220",
"162054502596379093864094100138052079297",
"306362243852346808614861351024610289507",
"84772691122130129346267929892591199670",
"106475485927887069795169520578428818879",
"760843948176936763736614088550450550",
"335271424882635951560873778971558878032",
"175621808709427662963164976335237869217",
"145714137223063175349171764531678955926",
"158727773730644317290685446922040039169"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "evhttp_get_request_connection",
"file": "http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72",
"id": "CVE-2026-63388-eb04d077",
"signature_version": "v1",
"digest": {
"length": 1418.0,
"function_hash": "229824989913640716274657054148484746048"
},
"signature_type": "Function"
},
{
"target": {
"function": "http_check_transfer_encoding_test",
"file": "test/regress_http.c"
},
"deprecated": false,
"source": "https://github.com/libevent/libevent/commit/79ddfb460847999b807cba76d04e73891f29c6ee",
"id": "CVE-2026-63388-ebc5ab94",
"signature_version": "v1",
"digest": {
"length": 554.0,
"function_hash": "159443554126248192493229143747497657830"
},
"signature_type": "Function"
}
]
"2026-08-22T16:16:23Z"