Skip to main content
EPSS 0.8%top 45%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
High
Published: 09/03/2026 (09/03/2026, 22:19:33 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Multiple security vulnerabilities were identified in libevent, an asynchronous event notification library, affecting various versions used in Red Hat and Ubuntu distributions. These include denial of service, HTTP request smuggling, buffer overflows, access control bypass, and arbitrary code execution issues. The vulnerabilities impact HTTP parsing, RPC data handling, and AF_UNIX socket processing. Fixes are available through official updates from Red Hat and Ubuntu, including Ubuntu Pro for extended support. Users are advised to apply the provided patches to mitigate these risks.

Affected software

Ubuntu:14.04:LTSmore threats →ghsa
libevent
pkg:deb/ubuntu/libevent?arch=source&distro=trusty
Affected versions
=2.0.21-stable-1=2.0.21-stable-1ubuntu1=2.0.21-stable-1ubuntu1.14.04.1=2.0.21-stable-1ubuntu1.14.04.2
Ubuntu:16.04:LTSmore threats →ghsa
libevent
pkg:deb/ubuntu/libevent?arch=source&distro=xenial
Affected versions
=2.0.21-stable-2=2.0.21-stable-2ubuntu0.16.04.1
Ubuntu:18.04:LTSmore threats →ghsa
libevent
pkg:deb/ubuntu/libevent?arch=source&distro=bionic
Affected versions
=2.1.8-stable-4=2.1.8-stable-4build1
Ubuntu:20.04:LTSmore threats →ghsa
libevent
pkg:deb/ubuntu/libevent?arch=source&distro=focal
Affected versions
=2.1.8-stable-4build1=2.1.11-stable-1~exp0=2.1.11-stable-1
Ubuntu:22.04:LTSmore threats →ghsa
libevent
pkg:deb/ubuntu/libevent?arch=source&distro=jammy
Affected versions
=2.1.12-stable-1=2.1.12-stable-1build1=2.1.12-stable-1build2=2.1.12-stable-1build3
Ubuntu:24.04:LTSmore threats →ghsa
libevent
pkg:deb/ubuntu/libevent?arch=source&distro=noble
Affected versions
=2.1.12-stable-9=2.1.12-stable-9ubuntu2
Ubuntu:26.04:LTSmore threats →ghsa
libevent
pkg:deb/ubuntu/libevent?arch=source&distro=resolute
Affected versions
=2.1.12-stable-10build1=2.1.12-stable-10build2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/01/2026, 20:03:39 UTC

Technical Analysis

The libevent library contains several security flaws: CVE-2026-63382 involves HTTP parser bugs enabling HTTP request smuggling; CVE-2026-63383 is a denial of service via malformed RPC data; CVE-2026-63384 is a denial of service via integer conversion error in evtag_unmarshal_header; CVE-2026-63385 involves HTTP header handling bugs leading to access control bypass; CVE-2026-63387 is an off-by-one stack buffer overflow causing denial of service or data corruption; CVE-2026-63388 is an arbitrary code execution vulnerability via heap out-of-bounds write in AF_UNIX handling. These issues affect multiple stable versions of libevent in Red Hat Hardened Images and various Ubuntu LTS releases. Official patches have been released by Red Hat and Ubuntu, including updates distributed via Ubuntu Pro for legacy versions.

Potential Impact

The vulnerabilities can lead to denial of service, HTTP request smuggling, access control bypass, data corruption, and arbitrary code execution. These impacts affect the confidentiality, integrity, and availability of systems using vulnerable libevent versions. The issues arise from improper handling of malformed RPC data, HTTP requests, HTTP headers, and AF_UNIX socket data. Exploitation could disrupt services or allow unauthorized actions depending on the specific flaw.

Mitigation Recommendations

Official patches are available from Red Hat and Ubuntu. Users should apply the security updates to libevent packages as provided by their distribution. For Ubuntu, fixes are included in standard system updates and Ubuntu Pro for extended support on older LTS releases. Red Hat users should update to libevent version 2.1.13-0.1.hum1 or later as per the Red Hat advisory. No additional mitigation steps are required beyond applying these updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
UBUNTU-CVE-2026-63382
Osv Schema Version
1.7.0
Ecosystems
["Ubuntu:14.04:LTS","Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
Cvss Version
4.0

Threat ID: 6a8c4c54acd9273b499be7d7

Added to database: 08/24/2026, 13:51:16 UTC

Last enriched: 10/01/2026, 20:03:39 UTC

Last updated: 10/08/2026, 06:48:18 UTC

Views: 62

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses