c-ares.c-ares is vulnerable to Use After Free
75
High Risk
Query completion in c-ares runs a query callback while that query is still linked in the channel lookup list, an incomplete fix for CVE-2025-31498. If the callback frees the query, or if ares_getaddrinfo() over TCP starts another lookup after the host query is already freed, the same object is used or freed again. A resolver can reach the TCP path with a truncated UDP response, a FORMERR that has no OPT record, and a connection reset. The fix detaches each query from the lookup list before the callback runs.
You are affected if you are using a version that falls within the vulnerable range.
c-ares.c-ares is vulnerable to Use After Free in versions 1.33.0 - 1.34.6.
Upgrade the c-ares.c-ares library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.