{"id":"AZL-96912","summary":"CVE-2026-63380 affecting package libtevent 0.14.1-1","details":"Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server-\u003ews_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha.","modified":"2026-09-20T05:32:18Z","published":"2026-08-20T18:16:35Z","upstream":["CVE-2026-63380"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63380"}],"affected":[{"package":{"name":"libtevent","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libtevent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.14.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96912.json"}}],"schema_version":"1.9.0"}