{"id":"CVE-2026-63387","aliases":["GHSA-58rx-7448-jw47"],"url":"https://o3.security/vulnerability/CVE-2026-63387","summary":"Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response","details":"Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.","published":"2026-08-20T17:53:41.863Z","modified":"2026-08-22T03:49:45.345125962Z","cvss":{"score":7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/libevent/libevent/releases/tag/release-2.1.13-stable"},{"type":"WEB","url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63387.json"},{"type":"ADVISORY","url":"https://github.com/libevent/libevent/security/advisories/GHSA-58rx-7448-jw47"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63387"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-22T03:49:45.345125962Z"}}