Intel

AIKIDO-2026-238349

c-ares.c-ares is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-69186 Published 5 days ago

53

Medium Risk

This Affects:

OSc-ares.c-ares
1.21.0 - 1.34.6
Fixed in 1.34.7
Are you affected? Scan for Free

TL;DR

c-ares allocates resource record arrays from the answer, authority, and additional counts in the DNS header before checking that the message holds those records. A 12 byte header that sets each count to 65535 forces a multi megabyte allocation that is released when the parse fails. A stream of those responses puts pressure on the allocator and can stall resolution. The fix rejects a record count that cannot fit in the remaining bytes before it allocates.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

c-ares.c-ares is vulnerable to Denial of Service (DoS) in versions 1.21.0 - 1.34.6.

How to fix this

Upgrade the c-ares.c-ares library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform