{"id":"CVE-2026-63384","aliases":["GHSA-45c6-qx49-89m8"],"url":"https://o3.security/vulnerability/CVE-2026-63384","summary":"Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value.","details":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","published":"2026-08-20T17:53:08.417Z","modified":"2026-08-22T03:49:47.362010970Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda","label":"libevent/libevent@109c164"},"references":[{"type":"WEB","url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"},{"type":"WEB","url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63384.json"},{"type":"ADVISORY","url":"https://github.com/libevent/libevent/security/advisories/GHSA-45c6-qx49-89m8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63384"},{"type":"FIX","url":"https://github.com/libevent/libevent/commit/109c16499282959d70f56ec3baf4c8b1e6646bda"},{"type":"FIX","url":"https://github.com/libevent/libevent/commit/5e3c6ebe342b34c5a9bcf48e9a32ad6708b9c416"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-22T03:49:47.362010970Z"}}