Intel

AIKIDO-2026-718251

c-ares.c-ares is vulnerable to Use After Free

Use After FreeCVE-2026-33630 Published 5 days ago

75

High Risk

This Affects:

OSc-ares.c-ares
1.33.0 - 1.34.6
Fixed in 1.34.7
Are you affected? Scan for Free

TL;DR

Query completion in c-ares runs a query callback while that query is still linked in the channel lookup list, an incomplete fix for CVE-2025-31498. If the callback frees the query, or if ares_getaddrinfo() over TCP starts another lookup after the host query is already freed, the same object is used or freed again. A resolver can reach the TCP path with a truncated UDP response, a FORMERR that has no OPT record, and a connection reset. The fix detaches each query from the lookup list before the callback runs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

c-ares.c-ares is vulnerable to Use After Free in versions 1.33.0 - 1.34.6.

How to fix this

Upgrade the c-ares.c-ares library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform