PT-2026-76579 · Libevent+2 · Libevent+2

CVE-2026-63381

·

Published

2026-07-01

·

Updated

2026-09-01

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Libevent versions prior to 2.1.13 Libevent versions prior to 2.2.2-alpha
Description A use-after-free issue exists in buffer.c when the evbuffer add buffer reference() function processes an output buffer where the out total len variable is zero. The evbuffer free all chains() function frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last with datap. Consequently, APPEND CHAIN MULTICAST dereferences the dangling chain pointer, which can lead to memory corruption or a process crash.
Recommendations Update to version 2.1.13. Update to version 2.2.2-alpha.

Exploit

Fix

Out of bounds Read

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-96915
AZL-96953
AZL-97527
AZL-97545
BDU:2026-12658
CVE-2026-63381
ECHO-B3A5-0D83-0D17
GHSA-C2PJ-CG4R-88C8
OESA-2026-3268
USN-8710-1

Affected Products

Libevent
Linuxmint
Ubuntu