Intel

AIKIDO-2026-743445

c-ares.c-ares is vulnerable to Use After Free

Use After FreeCVE-2025-31498 Published 5 days ago

83

High Risk

This Affects:

C++c-ares.c-ares
1.32.3 - 1.34.4
Fixed in 1.34.5
Are you affected? Scan for Free

TL;DR

When process_answer() queues a query again after a DNS cookie failure, missing EDNS support, or a TCP close right after the response, a failed send closes the connection. read_answers() still reads that closed connection to dequeue other responses, a use-after-free that crashes the process. The fix stops reading the connection once it has been closed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

c-ares.c-ares is vulnerable to Use After Free in versions 1.32.3 - 1.34.4.

How to fix this

Upgrade the c-ares.c-ares and/or the c-ares library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform