SUSE-SU-2026:4021-1

    Dashboard / Vulnerabilities / SUSE-SU-2026:4021-1

    SUSE-SU-2026:4021-1

    Published: 7 Sept 2026Last Modified: 13 Sept 2026

    Summary: Security update for c-ares

    Details: This update for c-ares fixes the following issues: - CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279). - CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955). - CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). - CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416). - CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). - CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: - updated to 1.36.8.

    Affected packages

    Package

    Name: c-ares

    Purl: pkg:rpm/suse/c-ares&distro=SUSE%20Linux%20Enterprise%20Micro%205.3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.34.8-150000.3.29.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2026:4021-1 | CVE-DB