Opened 3 months ago

Closed 2 months ago

#23540 closed enhancement (fixed)

libevent-2.1.13

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Changes in version 2.1.13-stable (01 July 2026)

 This release contains several security fixes, affecting users of the
 following modules: evbuffer, bufferevent, evtag, evrpc, evdns, evhttp.
 If you have a program that uses one of those modules,
 or if you distribute libevent, you should upgrade.

 Additionally, this release backports some small modernizations to
 the libevent codebase, to aid in compiling with the compilers
 released over the last few years.

 Security Fixes (evtag, evrpc):
 - Fix an out-of-bounds read in decode_tag_internal.
   (Found by @Brubbish. GHSA-fj29-64w6-73h6)
 - Fix an integer overflow in evtag_unmarshal_header.
   (Found by @Brubbish. GHSA-45c6-qx49-89m8)

 Security Fixes (evhttp):
 - Discard HTTP trailers, to prevent header smuggling attacks.
   (Found by @sebastianosrt. GHSA-2gmv-p5m7-98p6)
 - Restrict HTTP header parsing to prevent request smuggling.
   (Originally reported by @xclow3n; and then by @kodareef5,
   @nstaller0490, @AsafMeizneer, and @yaotushaozhu.
   GHSA-q39v-w2g7-gr8j.)
 - Treat CRLF and %00 more strictly in HTTP headers, to prevent
   parser mismatch attacks.
   (Reported by @xclow3n and @AsafMeizner. See GHSA-q39v-w2g7-gr8j,
   GHSA-jcwh-pvf2-73p2.)
 - Fix a heap out-of-bound write that could occur when using
   AF_UNIX sockets and compiling libevent with -DNDEBUG.
   (Found by @mat-mo. GHSA-cvq5-vrvr-j338)

 Security fixes (evbuffer, bufferevent):
 - Fixed a dangling pointer in evbuffer_add_reference.
   (Found by @DarkaMaul. GHSA-c2pj-cg4r-88c8)

 Security fixes (evdns):
 - Fix an out-of-bounds write in dnsname_to_labels
   when building a DNS response of 2^16 bytes.
   (Found by @sectroyer. GHSA-58rx-7448-jw47)

 Security fixes (example code):
 - Avoid using strcpy() in sample/http-server.c.
   (Reported by @sectroyer. GHSA-5rgj-2c58-7jrc.)

 Other fixes:
 - Backport fixes for numerous compiler warnings.
 - Backport fixes for compilation with openssl 3 and later.

Change History (3)

comment:1 by Joe Locash, 3 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 3 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 3712270d7a. Leaving open for SA.

comment:3 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-169 has been issued.

Note: See TracTickets for help on using tickets.