Описание
Security update for c-ares
This update for c-ares fixes the following issues:
Updat to c-ares 1.36.8.
- CVE-2026-33630: remotely triggerable use-after-free/double-free in query-completion handling via
ares_getaddrinfo()over TCP (bsc#1270416). - CVE-2026-69184: CPU exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290).
- CVE-2026-69186: memory amplification denial of service via unvalidated DNS header record counts (bsc#1276291).
Changes for c-ares:
- For details, see https://c-ares.org/changelog.html.
Список пакетов
openSUSE Leap 16.0
c-ares-devel-1.34.8-160000.1.1
c-ares-utils-1.34.8-160000.1.1
libcares2-1.34.8-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1270416
- SUSE Bug 1276290
- SUSE Bug 1276291
- SUSE CVE CVE-2026-33630 page
- SUSE CVE CVE-2026-69184 page
- SUSE CVE CVE-2026-69186 page
Описание
unknown
Затронутые продукты
openSUSE Leap 16.0:c-ares-devel-1.34.8-160000.1.1
openSUSE Leap 16.0:c-ares-utils-1.34.8-160000.1.1
openSUSE Leap 16.0:libcares2-1.34.8-160000.1.1
Ссылки
- CVE-2026-33630
- SUSE Bug 1270416
Описание
unknown
Затронутые продукты
openSUSE Leap 16.0:c-ares-devel-1.34.8-160000.1.1
openSUSE Leap 16.0:c-ares-utils-1.34.8-160000.1.1
openSUSE Leap 16.0:libcares2-1.34.8-160000.1.1
Ссылки
- CVE-2026-69184
- SUSE Bug 1276290
Описание
unknown
Затронутые продукты
openSUSE Leap 16.0:c-ares-devel-1.34.8-160000.1.1
openSUSE Leap 16.0:c-ares-utils-1.34.8-160000.1.1
openSUSE Leap 16.0:libcares2-1.34.8-160000.1.1
Ссылки
- CVE-2026-69186
- SUSE Bug 1276291