INFCSA-2024:3842: c-ares security update

Information about definition

Identificator: INFCSA-2024:3842

Type: security

Release date: 2025-09-24 19:07:05 UTC

Information about package

The c-ares C library defines asynchronous DNS (Domain Name System) requests and provides name resolving API.

Vulnerabilities description

  • CVE-2024-25629

    c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character in a new line, it can lead to attempting to read memory prior to the start of the given buffer which may result in a crash. This issue is fixed in c-ares 1.27.0. No known workarounds exist.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 4.4 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download