Description
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://github.com/c-ares/c-ares/security/advisories/GHSA-jq53-42q6-pqr5
Patch x_refsource_misc
https://github.com/c-ares/c-ares/commit/714bf5675c541bd1e668a8db8e67ce012651e618
Scores
CVSS v3
5.9
EPSS
0.0002
EPSS Percentile
5.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (1)
c-ares/c-ares
1.32.3 - 1.34.6
Published
Dec 08, 2025
Tracked Since
Feb 18, 2026