[ubuntu/resolute-security] libevent 2.1.12-stable-10ubuntu0.2 (Accepted)
Kyle Kernick
kyle.kernick at canonical.com
Mon Sep 28 16:51:14 UTC 2026
libevent (2.1.12-stable-10ubuntu0.2) resolute-security; urgency=medium
* SECURITY UPDATE: Out-of-bounds write in dnsname_to_labels.
- debian/patches/CVE-2026-63387.patch: Correct off-by-one error in
evdns.c
- CVE-2026-63387
* SECURITY UPDATE: Heap out-of-bounds write via AF_UNIX+http+NDEBUG.
- debian/patches/CVE-2026-63388.patch: Allocate enough memory for AF_UNIX
addresses and check length in bufferevent-internal.h,
bufferevent_sock.c, and http.c
- CVE-2026-63388
Date: 2026-09-23 23:34:12.114239+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/libevent/2.1.12-stable-10ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list