CVE-2026-63383: Libevent: decode_tag_internal() can lead to out-of-bounds read

Published Aug 20, 2026
·
Updated

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in eventtagging.c when decodetaginternal requests at most five bytes from evbufferpullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.

Affected Software

1 affected component
libevent libevent>2.1.12<=2.1.13, <2.1.13, <2.2.2-alpha

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade libevent to a version that resolves this vulnerability.

    Fixed in 2.1.13
  2. Upgrade

    Upgrade libevent to a version that resolves this vulnerability.

    Fixed in 2.2.2-alpha

Event History

Aug 20, 2026
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are realistically exposed?

Processes using affected libevent versions are exposed if they decode attacker-controlled tagged RPC data. Exploitation specifically requires the input to be held in a fragmented evbuffer.

2

What does an attacker need to send to trigger the flaw?

The attacker needs to supply a fragmented evbuffer containing a malformed six-byte tag. This causes tag decoding to advance beyond the contiguous data returned by evbuffer_pullup.

3

What is the likely impact of successful exploitation?

The out-of-bounds read can crash the process performing the decode. The provided information does not establish impacts beyond a process crash.

4

How can I determine whether an installed version is fixed?

The issue is fixed in libevent 2.1.13 and 2.2.2-alpha. Versions prior to 2.1.13 and 2.2.2-alpha are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203