Views
5

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8710-1 updates libevent on Ubuntu 24.04 LTS to address multiple security issues, including a use-after-free, HTTP request smuggling, out-of-bounds read, resource exhaustion, and security restriction bypasses. The affected package versions are `2.1.12-stable-9ubuntu2.1`.

Update Details

Security

  • Fixes a use-after-free in handling certain empty output buffers that could lead to denial of service or arbitrary code execution (CVE-2026-63381).
  • Fixes HTTP request boundary desynchronization that could enable HTTP request smuggling (CVE-2026-63382).
  • Fixes an out-of-bounds read in malformed tagged RPC data handling that could cause denial of service (CVE-2026-63383).
  • Fixes excessive resource consumption from large tagged RPC payload lengths that could cause denial of service (CVE-2026-63384).
  • Fixes inconsistent handling of certain HTTP URIs and header values that could bypass security restrictions (CVE-2026-63385).

Hints

  • A standard system update is sufficient to apply the fixes.
  • For Ubuntu 24.04 LTS (noble), update libevent-2.1-7t64, libevent-core-2.1-7t64, libevent-dev, and libevent-extra-2.1-7t64 to 2.1.12-stable-9ubuntu2.1.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 24.04 LTS (Noble Numbat)

Version: 2.1.12-stable-9ubuntu2.1

Vendor release date: Sep 1, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 6, 2026

Description: Server operating system for Linux infrastructure and workloads.