Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. This issue is fixed in versions 2.1.13 and 2.2.2-alpha.
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | libevent-0:2.1.13-1.el10_2 | * |
| Red Hat Enterprise Linux 8 | RedHat | libevent-0:2.1.8-11.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | libevent-0:2.1.8-11.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | libevent-0:2.1.13-1.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | libevent-0:2.1.13-1.el9_8 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1790223279 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1790223719 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-operator-rhel9:1790272426 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/jetstack-cert-manager-rhel9:1790589912 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-istio-csr-rhel9:1790589914 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-operator-rhel9:1790589855 | * |
| Red Hat Hardened Images | RedHat | libevent-main-2.1.12-19.1.hum1 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-kubernetes-rhel9:1790241897 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1790241954 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1790241900 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1790241922 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1790242004 | * |
| Libevent | Ubuntu | esm-infra/bionic | * |
| Libevent | Ubuntu | esm-infra/focal | * |
| Libevent | Ubuntu | jammy | * |
| Libevent | Ubuntu | noble | * |
| Libevent | Ubuntu | resolute | * |
While assertion is good for catching logic errors and reducing the chances of reaching more serious vulnerability conditions, it can still lead to a denial of service. For example, if a server handles multiple simultaneous connections, and an assert() occurs in one single connection that causes all other connections to be dropped, this is a reachable assertion that leads to a denial of service.