Linuxsecurity Critical libevent Vulnerabilities Affecting Multiple Ubuntu Versions
Article Content
- •Two critical vulnerabilities in libevent affect multiple Ubuntu LTS versions.
- •Remote and local attackers can exploit these flaws for denial of service or code execution.
- •Patches are available; immediate updates are recommended for affected systems.
Two vulnerabilities in the libevent library were discovered by Michał Majchrowicz and Marcin Wyczechowski, allowing remote and local attackers to potentially execute arbitrary code or cause denial of service. The vulnerabilities, identified as CVE-2026-63387 and CVE-2026-63388, affect Ubuntu versions 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS. Users are advised to update their systems to mitigate these risks. The vulnerabilities were published on August 20, 2026, and are confirmed to be exploitable. Affected users should prioritize applying the available patches to secure their systems. The issues stem from improper handling of DNS responses and connections within the library. CISA has confirmed the exploitation of these vulnerabilities, emphasizing the urgency of the situation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2026-63387 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Security Flaws in Fedora libevent 2.1.13 Require Immediate Attention Fedora has released critical security updates for libevent version 2.1.13, addressing multiple vulnerabilities including CVE-2026-63379, CVE-2026-63381, CVE-2026-63382, CVE-2026-63383, CVE-2026-63384, CVE-2026-63385, CVE-2026-63387, and CVE-2026-63388. These vulnerabilities, published on August 20, 2026, include…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…