{"id":"RHSA-2026:67908","summary":"Red Hat Security Advisory: libevent security update","modified":"2026-09-17T10:30:24.691877622Z","published":"2026-09-17T10:18:08Z","upstream":["CVE-2026-63382","CVE-2026-63383","CVE-2026-63384","CVE-2026-63385","CVE-2026-63387","CVE-2026-63388"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67908"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520654"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520655"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520658"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520660"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520661"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520666"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67908.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-63382"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63382"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63382"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/10abb34b8dc3e1184de315dd261ce4b77563cda6"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/5119ceb00557bf007f9065709e852686f3c0bb6e"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/83ba67373032334559b82409db035dd8c3cc1660"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/ac38703b2d312200c4f967f02936af0118d384a0"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/security/advisories/GHSA-q39v-w2g7-gr8j"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-63383"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63383"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63383"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/91ed8745eebabdd27592a83d350338a8c4626321"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/e1f9e21887c6b104e206a718385ba3ffc75180cb"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/security/advisories/GHSA-fj29-64w6-73h6"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-63384"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63384"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63384"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-63385"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63385"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63385"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/758be0c0f69c1934ef9a84ab39e9f9e5fde2e6d0"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/9170dd35e64714613e8d13b290587cfc28e258e2"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/security/advisories/GHSA-jcwh-pvf2-73p2"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-63387"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63387"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63387"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-63388"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63388"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63388"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/52057cb33d0c20c0a0453fbabe6c0c96854931b9"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/commit/ef38f926e9cd1f082416c6fff13587bc1f431d72"},{"type":"ARTICLE","url":"https://github.com/libevent/libevent/security/advisories/GHSA-cvq5-vrvr-j338"}],"affected":[{"package":{"name":"libevent-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/libevent-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.1.8-11.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67908.json"}},{"package":{"name":"libevent-debugsource","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/libevent-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.1.8-11.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67908.json"}},{"package":{"name":"libevent-devel","ecosystem":"Red Hat:enterprise_linux:8::appstream","purl":"pkg:rpm/redhat/libevent-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.1.8-11.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67908.json"}},{"package":{"name":"libevent","ecosystem":"Red Hat:enterprise_linux:8::baseos","purl":"pkg:rpm/redhat/libevent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.1.8-11.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67908.json"}},{"package":{"name":"libevent-debuginfo","ecosystem":"Red Hat:enterprise_linux:8::baseos","purl":"pkg:rpm/redhat/libevent-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.1.8-11.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67908.json"}},{"package":{"name":"libevent-debugsource","ecosystem":"Red Hat:enterprise_linux:8::baseos","purl":"pkg:rpm/redhat/libevent-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.1.8-11.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67908.json"}},{"package":{"name":"libevent-doc","ecosystem":"Red Hat:enterprise_linux:8::baseos","purl":"pkg:rpm/redhat/libevent-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.1.8-11.el8_10"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67908.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}