[CLSA-2026:1790709490] Fix CVE(s): CVE-2026-63383, CVE-2026-63384, CVE-2026-63387, CVE-2026-63388
Type:
security
Severity:
Important
Release date:
2026-09-29 19:18:24 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in decode_tag_internal() - debian/patches/CVE-2026-63383.patch: bound the tag decoding loop by the pulled-up length instead of the full buffer length in event_tagging.c - CVE-2026-63383 * SECURITY UPDATE: integer overflow in evtag_unmarshal_header() - debian/patches/CVE-2026-63384.patch: reject payload lengths above INT_MAX in event_tagging.c, include/event2/tag.h - CVE-2026-63384 * SECURITY UPDATE: heap out-of-bounds write in bufferevent_socket_set_conn_address_() via an AF_UNIX peer address - debian/patches/CVE-2026-63388.patch: check the address length regardless of NDEBUG, fail the connection on an over-long address and make conn_address large enough for AF_UNIX in bufferevent_sock.c, bufferevent-internal.h, http.c - CVE-2026-63388 * SECURITY UPDATE: off-by-one stack buffer overflow in dnsname_to_labels() - debian/patches/CVE-2026-63387.patch: refuse to write the terminating label byte past the end of the buffer in evdns.c - CVE-2026-63387
Updated packages:
  • libevent-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
    sha:c4b225ad2362e6fe1736ec2b9de2a78cd872289c
  • libevent-core-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
    sha:fab8abb04e3558bae1e118407ba08b721956153c
  • libevent-dev_2.1.12-stable-1+tuxcare.els1_amd64.deb
    sha:0144734bf8ac92878504f38bf20ac72878096282
  • libevent-extra-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
    sha:0e42f55f620c478cf8ee933b06bbd05e51781679
  • libevent-openssl-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
    sha:f84d255af5a780412619776f949d7c45119dc316
  • libevent-pthreads-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
    sha:e17dfae3d6bb33027cfe13e5f309eb4271145bcf
  • libevent-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
    sha:f55e8f1dc3ccb17514e28b7521955450da96b1c6
  • libevent-core-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
    sha:3e30a072b045c30f73082d4a077f6f9bd472d300
  • libevent-dev_2.1.12-stable-1+tuxcare.els1_arm64.deb
    sha:b6d888d2bdefc2f4a53c8c937cdc1cc5fdaee932
  • libevent-extra-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
    sha:e1b04dd749a42ed5c76b79c2a9af13f1bbd17783
  • libevent-openssl-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
    sha:71454b9b04124f77b13ca5865eaa5f7c3480a2c2
  • libevent-pthreads-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
    sha:a024a4382eb0c91d7c1c369b2ffee8387c866e91
  • libevent-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
    sha:8ce2b4ca89deac4ab76ce3b8a8e1593525854f61
  • libevent-core-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
    sha:5ad785287929b04d694ed2ad121eec8e3a3141d8
  • libevent-dev_2.1.12-stable-1+tuxcare.els1_armel.deb
    sha:a96a7b0092bb2bed314772e85a9ea1b2ffda1627
  • libevent-extra-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
    sha:a2efc380c84a4fcf94192504e1d3cae9d3920df9
  • libevent-openssl-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
    sha:8e5e3074fbcaa0aebf889555bfa1db0f105daf3a
  • libevent-pthreads-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
    sha:91f968216598c4b1f480ed03c54797a581a8a39f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.