[El-errata] ELSA-2026-67908 Important: Oracle Linux 8 libevent security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Mon Sep 21 13:24:35 UTC 2026
Oracle Linux Security Advisory ELSA-2026-67908
http://linux.oracle.com/errata/ELSA-2026-67908.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
libevent-2.1.8-11.el8_10.i686.rpm
libevent-2.1.8-11.el8_10.x86_64.rpm
libevent-devel-2.1.8-11.el8_10.i686.rpm
libevent-devel-2.1.8-11.el8_10.x86_64.rpm
libevent-doc-2.1.8-11.el8_10.noarch.rpm
aarch64:
libevent-2.1.8-11.el8_10.aarch64.rpm
libevent-devel-2.1.8-11.el8_10.aarch64.rpm
libevent-doc-2.1.8-11.el8_10.noarch.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/libevent-2.1.8-11.el8_10.src.rpm
Related CVEs:
CVE-2026-63382
CVE-2026-63383
CVE-2026-63384
CVE-2026-63385
CVE-2026-63387
CVE-2026-63388
Description of changes:
[2.1.8-11]
- Fix CVE-2026-63385: HTTP header injection via CRLF in header values
- Resolves: RHEL-253566
[2.1.8-10]
- Fix CVE-2026-63387: out-of-bounds write in evdns dnsname_to_labels
- Resolves: RHEL-249889
[2.1.8-9]
- Fix CVE-2026-63383: out-of-bounds read in decode_tag_internal
- Resolves: RHEL-250240
[2.1.8-8]
- Fix CVE-2026-63384: integer overflow in evtag_unmarshal_header
- Resolves: RHEL-250071
[2.1.8-7]
- Fix CVE-2026-63388: heap out-of-bounds write via AF_UNIX+http+NDEBUG
- Resolves: RHEL-250045
[2.1.8-6]
- Fix CVE-2026-63382: HTTP request smuggling via Transfer-Encoding
- Resolves: RHEL-253525
More information about the El-errata
mailing list