Debian dla-4786 : libevent-2.1-7 - security update

critical Nessus Plugin ID 348186

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4786 advisory.

------------------------------------------------------------------------- Debian LTS Advisory DLA-4786-1 [email protected] https://www.debian.org/lts/security/ Andreans Henriksson September 18, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : libevent Version : 2.1.12-stable-8+deb12u1 CVE ID : CVE-2026-63379 CVE-2026-63381 CVE-2026-63382 CVE-2026-63383 CVE-2026-63384 CVE-2026-63385 CVE-2026-63387 CVE-2026-63388 Debian Bug :

Multiple vulnerabilities has been found in libevent, an event notification library.

CVE-2026-63379 (GHSA-2gmv-p5m7-98p6)

Sebastianosrt discovered that libevent's HTTP implementation did not properly handle HTTP trailers. This could allow trailer headers to be interpreted as regular request headers, potentially resulting in HTTP header smuggling and request interpretation differences.

CVE-2026-63381 (GHSA-c2pj-cg4r-88c8)

DarkaMaul discovered a dangling pointer in evbuffer_add_buffer_reference(). When the output buffer contained an empty chain, the chain could be freed without updating the corresponding buffer pointers before it was subsequently reused. This could result in memory corruption or a denial of service.

CVE-2026-63382 (GHSA-q39v-w2g7-gr8j)

Xclow3n discovered that libevent's HTTP parser incorrectly handled Transfer-Encoding headers and chunked request framing. The issue could cause libevent and an HTTP proxy to disagree about request boundaries, allowing HTTP request smuggling.

CVE-2026-63383 (GHSA-fj29-64w6-73h6)

Brubbish discovered an out-of-bounds read in the tagged RPC parsing code.
Processing a malformed RPC tag could cause libevent to read beyond the available buffer, potentially resulting in a denial of service.

CVE-2026-63384 (GHSA-45c6-qx49-89m8)

Brubbish discovered an integer overflow in evtag_unmarshal_header().
An attacker able to supply a specially crafted tagged RPC message could cause an incorrect length calculation, potentially resulting in memory allocation or parsing errors and a denial of service.

CVE-2026-63385 (GHSA-jcwh-pvf2-73p2)

AsafMeizner discovered HTTP parsing issues involving percent-encoded NUL bytes and obsolete folded headers. These parsing differences could allow a frontend HTTP proxy and a libevent-based backend to interpret a request differently, potentially resulting in access control bypass or header injection.

CVE-2026-63387 (GHSA-58rx-7448-jw47)

Sectroyer discovered an off-by-one stack buffer overflow in the DNS server code. A specially crafted DNS response could trigger an out-of-bounds write when constructing a DNS response of a particular size, potentially resulting in a denial of service or memory corruption.

CVE-2026-63388 (GHSA-cvq5-vrvr-j338)

Mat-mo discovered a heap-based out-of-bounds write in the socket handling code. When accepting an AF_UNIX connection, an attacker-controlled peer address could be copied into a buffer that was too small when assertions were disabled. This could result in memory corruption and potentially arbitrary code execution.


For Debian 12 bookworm, these problems have been fixed in version 2.1.12-stable-8+deb12u1.

We recommend that you upgrade your libevent packages.

For the detailed security status of libevent please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/libevent

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Attachment:
signature.asc Description: PGP signature

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libevent-2.1-7 packages.

See Also

https://packages.debian.org/source/bookworm/libevent

https://security-tracker.debian.org/tracker/CVE-2026-63379

https://security-tracker.debian.org/tracker/CVE-2026-63381

https://security-tracker.debian.org/tracker/CVE-2026-63382

https://security-tracker.debian.org/tracker/CVE-2026-63383

https://security-tracker.debian.org/tracker/CVE-2026-63384

https://security-tracker.debian.org/tracker/CVE-2026-63385

https://security-tracker.debian.org/tracker/CVE-2026-63387

https://security-tracker.debian.org/tracker/CVE-2026-63388

https://security-tracker.debian.org/tracker/source-package/libevent

Plugin Details

Severity: Critical

ID: 348186

File Name: debian_DLA-4786.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.17

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS Score Source: CVE-2026-63387

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-63388

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 7.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:N

CVSS Score Source: CVE-2026-63385

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:libevent-2.1-7, p-cpe:/a:debian:debian_linux:libevent-core-2.1-7, p-cpe:/a:debian:debian_linux:libevent-dev, p-cpe:/a:debian:debian_linux:libevent-extra-2.1-7, p-cpe:/a:debian:debian_linux:libevent-openssl-2.1-7, p-cpe:/a:debian:debian_linux:libevent-pthreads-2.1-7

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/18/2026

Vulnerability Publication Date: 8/20/2026

Reference Information

CVE: CVE-2026-63379, CVE-2026-63381, CVE-2026-63382, CVE-2026-63383, CVE-2026-63384, CVE-2026-63385, CVE-2026-63387, CVE-2026-63388