CVE-2026-63381 - Medium Severity Vulnerability
Vulnerable Library - src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Found in base branches: stable/4.0, master
Vulnerable Source Files (1)
Vulnerability Details
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.
Publish Date: 2026-08-20
URL: CVE-2026-63381
CVSS 3 Score Details (6.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-20
Fix Resolution: https://github.com/libevent/libevent.git - release-2.1.13-stable,https://github.com/libevent/libevent.git - release-2.2.2-alpha
Step up your Open Source Security Game with Mend here
CVE-2026-63381 - Medium Severity Vulnerability
Library home page: https://github.com/MidnightBSD/src.git
Found in base branches: stable/4.0, master
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.
Publish Date: 2026-08-20
URL: CVE-2026-63381
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-08-20
Fix Resolution: https://github.com/libevent/libevent.git - release-2.1.13-stable,https://github.com/libevent/libevent.git - release-2.2.2-alpha
Step up your Open Source Security Game with Mend here