Libevent: Prior to 2.1.13 and 2.2.2-a ...) (CVE-2026-63385)
A vulnerability exists in libevent, an event notification library, affecting multiple stable versions prior to 2.1.13 and 2.2.2-a. The issue is identified as CVE-2026-63385 and impacts various Ubuntu LTS releases. The vulnerability has a medium severity rating based on CVSS 4.0 metrics, indicating network attack vector with low attack complexity but partial attack and impact requirements. No known exploits are reported in the wild. Patch status is not confirmed due to lack of vendor advisory or patch links.
AI Analysis
Technical Summary
CVE-2026-63385 affects libevent versions prior to 2.1.13 and 2.2.2-a, which is an event notification library widely used in various Ubuntu LTS distributions. The vulnerability has a CVSS 4.0 vector indicating it can be exploited remotely without privileges or user interaction, but requires partial attack and impact conditions. The severity is medium, reflecting limited but notable impact. No detailed technical exploit or impact specifics are provided in the source data. Multiple Ubuntu LTS versions are affected, including 14.04 through 26.04. No official patch or remediation details are available in the provided data.
Potential Impact
The vulnerability allows remote attackers to potentially exploit libevent without requiring privileges or user interaction, with partial attack and impact conditions. The impact is rated medium severity, indicating a moderate risk of compromise or disruption. There are no known exploits in the wild, and no detailed impact scenarios are described in the source data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor vendor communications for updates. No specific mitigation steps are indicated in the available data.
Libevent: Prior to 2.1.13 and 2.2.2-a ...) (CVE-2026-63385)
Description
A vulnerability exists in libevent, an event notification library, affecting multiple stable versions prior to 2.1.13 and 2.2.2-a. The issue is identified as CVE-2026-63385 and impacts various Ubuntu LTS releases. The vulnerability has a medium severity rating based on CVSS 4.0 metrics, indicating network attack vector with low attack complexity but partial attack and impact requirements. No known exploits are reported in the wild. Patch status is not confirmed due to lack of vendor advisory or patch links.
CVSS v4.0
Affected software
pkg:deb/ubuntu/libevent?arch=source&distro=trustypkg:deb/ubuntu/libevent?arch=source&distro=xenialpkg:deb/ubuntu/libevent?arch=source&distro=bionicpkg:deb/ubuntu/libevent?arch=source&distro=focalpkg:deb/ubuntu/libevent?arch=source&distro=jammypkg:deb/ubuntu/libevent?arch=source&distro=noblepkg:deb/ubuntu/libevent?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-63385 affects libevent versions prior to 2.1.13 and 2.2.2-a, which is an event notification library widely used in various Ubuntu LTS distributions. The vulnerability has a CVSS 4.0 vector indicating it can be exploited remotely without privileges or user interaction, but requires partial attack and impact conditions. The severity is medium, reflecting limited but notable impact. No detailed technical exploit or impact specifics are provided in the source data. Multiple Ubuntu LTS versions are affected, including 14.04 through 26.04. No official patch or remediation details are available in the provided data.
Potential Impact
The vulnerability allows remote attackers to potentially exploit libevent without requiring privileges or user interaction, with partial attack and impact conditions. The impact is rated medium severity, indicating a moderate risk of compromise or disruption. There are no known exploits in the wild, and no detailed impact scenarios are described in the source data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor vendor communications for updates. No specific mitigation steps are indicated in the available data.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-63385
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:14.04:LTS","Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a8c4c52acd9273b499be794
Added to database: 08/24/2026, 13:51:14 UTC
Last enriched: 08/24/2026, 14:06:45 UTC
Last updated: 08/24/2026, 22:52:13 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.