{"apiVersion":"1.0","identifier":"CVE-2026-63388","description":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","publishedAt":"2026-08-20T18:16:36","lastModifiedAt":"2026-08-21T22:16:42","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63388","cvssScore":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00142,"riskScore":0.85,"affectedProduct":"libevent","affectedVersions":"<2.1.13, <2.2.2-alpha","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-63388","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-63388","en":"https://www.redsauce.net/en/cves/CVE-2026-63388","fr":"https://www.redsauce.net/fr/cves/CVE-2026-63388","pt":"https://www.redsauce.net/pt/cves/CVE-2026-63388","de":"https://www.redsauce.net/de/cves/CVE-2026-63388","sk":"https://www.redsauce.net/sk/cves/CVE-2026-63388","el":"https://www.redsauce.net/el/cves/CVE-2026-63388"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-63388"}}