Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS… (CVE-2026-63387)
Description
Libevent versions prior to 2.1.13 and 2.2.2-alpha contain an off-by-one stack buffer overflow in the evdns.c component. This occurs when the dnsname_to_labels function formats a DNS record name at the end of a 64 KB stack buffer, allowing a one-byte out-of-bounds write. Crafted DNS server responses with PTR, CNAME, MX, NS, or SOA records can trigger this overflow, potentially causing process crashes or memory corruption. The issue is fixed in libevent versions 2.1.13 and 2.2.2-alpha.
CVSS v3.1
Score 7.0high
Affected software
pkg:deb/ubuntu/libevent?arch=source&distro=trustypkg:deb/ubuntu/libevent?arch=source&distro=xenialpkg:deb/ubuntu/libevent?arch=source&distro=bionicpkg:deb/ubuntu/libevent?arch=source&distro=focalpkg:deb/ubuntu/libevent?arch=source&distro=jammypkg:deb/ubuntu/libevent?arch=source&distro=noblepkg:deb/ubuntu/libevent?arch=source&distro=resolutepkg:deb/ubuntu/libevent?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/libevent?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/libevent?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/libevent?arch=source&distro=esm-infra/focalRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Libevent, an event notification library, has a stack buffer overflow vulnerability (CVE-2026-63387) in versions prior to 2.1.13 and 2.2.2-alpha. The vulnerability arises in evdns.c within the dnsname_to_labels function, which improperly handles the final-label check when formatting DNS record names. This permits a one-byte out-of-bounds write beyond the allocated 64 KB stack buffer in evdns_server_request_format_response. Maliciously crafted DNS responses containing PTR, CNAME, MX, NS, or SOA data can exploit this flaw to crash or corrupt the affected process. The vulnerability is resolved in libevent 2.1.13 and 2.2.2-alpha.
Potential Impact
Exploitation of this vulnerability can lead to a one-byte stack buffer overflow, causing process crashes or memory corruption. The impact includes potential denial of service or integrity issues due to corrupted memory. There is no confirmed evidence of active exploitation in the wild.
Mitigation Recommendations
Upgrade libevent to version 2.1.13 or later, or 2.2.2-alpha or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-63387
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:14.04:LTS","Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a8c4c52acd9273b499be792
Added to database: 08/24/2026, 13:51:14 UTC
Last enriched: 09/29/2026, 05:10:41 UTC
Last updated: 10/08/2026, 06:48:18 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.