Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33630

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in c-ares. A use-after-free / double-free vulnerability exists in the query-completion handling path, where a query callback is invoked while the query is still linked in internal lookup structures. A remote attacker can exploit this via ares_getaddrinfo() over TCP by sending crafted DNS responses that force an EDNS-downgrade retry followed by a connection reset, causing the internal completion handler to access freed memory. This leads to memory corruption and a crash (denial of service), with potential for further impact depending on the allocator and build configuration.

Отчет

A use-after-free / double-free vulnerability was found in c-ares' query-completion handling. The flaw is remotely exploitable without application cooperation via ares_getaddrinfo() over TCP: a malicious or on-path DNS server can force a specific sequence of responses (FORMERR without OPT record, duplicate query ID response, TCP reset) that causes the internal completion handler to access freed memory. An attacker can force the client onto TCP by setting the truncation (TC) bit in a UDP response. The consequence is memory corruption leading to a crash (denial of service). This is a broader fix for the pattern previously addressed in CVE-2025-31498. All versions of c-ares prior to 1.34.7 are affected.

Меры по смягчению последствий

There is no complete mitigation for the remotely-triggered path. As a partial mitigation, use trusted DNS resolvers reached over a trusted transport (e.g., DNS-over-TLS). Avoid calling ares_cancel() from within a query callback to prevent the application-triggered path. Upgrade to c-ares 1.34.7 or later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6c-aresOut of support scope
Red Hat Enterprise Linux 7c-aresNot affected
Red Hat Enterprise Linux 8c-aresNot affected
Red Hat Enterprise Linux 9c-aresNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10c-aresFixedRHSA-2026:4209620.07.2026
Red Hat Hardened Imagesc-ares-main-1.34.7-1.hum1FixedRHSA-2026:3619207.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2497686c-ares: c-ares: Use-after-free / double-free in query-completion handling

7.5 High

CVSS3

Связанные уязвимости

ubuntu
22 дня назад

[Unknown description]

debian

Описание отсутствует

rocky
9 дней назад

Important: c-ares security update

oracle-oval
10 дней назад

ELSA-2026-42096: c-ares security update (IMPORTANT)

7.5 High

CVSS3