Release date:
2026-09-29 19:18:24 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in decode_tag_internal()
- debian/patches/CVE-2026-63383.patch: bound the tag decoding loop by the
pulled-up length instead of the full buffer length in event_tagging.c
- CVE-2026-63383
* SECURITY UPDATE: integer overflow in evtag_unmarshal_header()
- debian/patches/CVE-2026-63384.patch: reject payload lengths above
INT_MAX in event_tagging.c, include/event2/tag.h
- CVE-2026-63384
* SECURITY UPDATE: heap out-of-bounds write in
bufferevent_socket_set_conn_address_() via an AF_UNIX peer address
- debian/patches/CVE-2026-63388.patch: check the address length
regardless of NDEBUG, fail the connection on an over-long address and
make conn_address large enough for AF_UNIX in bufferevent_sock.c,
bufferevent-internal.h, http.c
- CVE-2026-63388
* SECURITY UPDATE: off-by-one stack buffer overflow in dnsname_to_labels()
- debian/patches/CVE-2026-63387.patch: refuse to write the terminating
label byte past the end of the buffer in evdns.c
- CVE-2026-63387
Updated packages:
-
libevent-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
sha:c4b225ad2362e6fe1736ec2b9de2a78cd872289c
-
libevent-core-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
sha:fab8abb04e3558bae1e118407ba08b721956153c
-
libevent-dev_2.1.12-stable-1+tuxcare.els1_amd64.deb
sha:0144734bf8ac92878504f38bf20ac72878096282
-
libevent-extra-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
sha:0e42f55f620c478cf8ee933b06bbd05e51781679
-
libevent-openssl-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
sha:f84d255af5a780412619776f949d7c45119dc316
-
libevent-pthreads-2.1-7_2.1.12-stable-1+tuxcare.els1_amd64.deb
sha:e17dfae3d6bb33027cfe13e5f309eb4271145bcf
-
libevent-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
sha:f55e8f1dc3ccb17514e28b7521955450da96b1c6
-
libevent-core-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
sha:3e30a072b045c30f73082d4a077f6f9bd472d300
-
libevent-dev_2.1.12-stable-1+tuxcare.els1_arm64.deb
sha:b6d888d2bdefc2f4a53c8c937cdc1cc5fdaee932
-
libevent-extra-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
sha:e1b04dd749a42ed5c76b79c2a9af13f1bbd17783
-
libevent-openssl-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
sha:71454b9b04124f77b13ca5865eaa5f7c3480a2c2
-
libevent-pthreads-2.1-7_2.1.12-stable-1+tuxcare.els1_arm64.deb
sha:a024a4382eb0c91d7c1c369b2ffee8387c866e91
-
libevent-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
sha:8ce2b4ca89deac4ab76ce3b8a8e1593525854f61
-
libevent-core-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
sha:5ad785287929b04d694ed2ad121eec8e3a3141d8
-
libevent-dev_2.1.12-stable-1+tuxcare.els1_armel.deb
sha:a96a7b0092bb2bed314772e85a9ea1b2ffda1627
-
libevent-extra-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
sha:a2efc380c84a4fcf94192504e1d3cae9d3920df9
-
libevent-openssl-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
sha:8e5e3074fbcaa0aebf889555bfa1db0f105daf3a
-
libevent-pthreads-2.1-7_2.1.12-stable-1+tuxcare.els1_armel.deb
sha:91f968216598c4b1f480ed03c54797a581a8a39f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.