Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-62408

Опубликовано: 08 дек. 2025
Источник: redhat
CVSS3: 5.9

Описание

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

A flaw was found in c-ares. This vulnerability allows a Denial of Service (DoS) via terminating a query after maximum attempts when using read_answer() and process_answer() functions.

Отчет

This vulnerability is rated Moderate for Red Hat products. The flaw in c-ares can lead to a Denial of Service when the library is used to resolve queries, specifically when read_answer() and process_answer() functions are called and a query terminates after maximum attempts. This could impact applications that rely on c-ares for asynchronous DNS resolution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10c-aresFix deferred
Red Hat Enterprise Linux 10nodejs22Fix deferred
Red Hat Enterprise Linux 10nodejs24Fix deferred
Red Hat Enterprise Linux 6c-aresOut of support scope
Red Hat Enterprise Linux 7c-aresOut of support scope
Red Hat Enterprise Linux 8c-aresFix deferred
Red Hat Enterprise Linux 8nodejs:20/nodejsFix deferred
Red Hat Enterprise Linux 8nodejs:22/nodejsFix deferred
Red Hat Enterprise Linux 8nodejs:24/nodejsFix deferred
Red Hat Enterprise Linux 9c-aresFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2420217c-ares: c-ares: Denial of Service due to query termination after maximum attempts

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

CVSS3: 5.9
nvd
4 месяца назад

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.

CVSS3: 5.9
msrc
4 месяца назад

c-ares has a Use After Free vulnerability when connection is cleaned up after error

CVSS3: 5.9
debian
4 месяца назад

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1. ...

5.9 Medium

CVSS3