Compiler Removal of Code to Clear Buffers in libevent - #VU136945

 

Compiler Removal of Code to Clear Buffers in libevent - #VU136945

Published: July 6, 2026


Vulnerability identifier: #VU136945
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-14
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to compiler removal of code to clear buffers in sha1.c when processing SHA1 input through the public API. A remote attacker can leverage a memory read primitive to disclose sensitive information.

Sensitive SHA1 input blocks, intermediate hash state, and counter data may remain on the stack after the affected functions return.


Affected software

libevent

Remediation

Install security update from vendor's website.

libevent - update to 2.2.2 alpha

External References

Related Security Bulletins