SUSE-SU-2026:4021-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4021-1
SUSE-SU-2026:4021-1
Summary: Security update for c-ares
Details: This update for c-ares fixes the following issues: - CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279). - CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955). - CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). - CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416). - CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). - CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: - updated to 1.36.8.
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264021-1/, https://bugzilla.suse.com/1220279, https://bugzilla.suse.com/1240955, https://bugzilla.suse.com/1254738, https://bugzilla.suse.com/1270416, https://bugzilla.suse.com/1276290, https://bugzilla.suse.com/1276291, https://www.suse.com/security/cve/CVE-2024-25629, https://www.suse.com/security/cve/CVE-2025-31498, https://www.suse.com/security/cve/CVE-2025-62408, https://www.suse.com/security/cve/CVE-2026-33630, https://www.suse.com/security/cve/CVE-2026-69184, https://www.suse.com/security/cve/CVE-2026-69186
Affected packages
Package
Name: c-ares
Purl: pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Micro%205.3
Affected ranges
Type: ECOSYSTEM
Events:
