CVE-2026-69186

EUVD-2026-83212
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
c-ares
bookworm
1.18.1-3
fixed
bullseye
not-affected
forky
1.34.8-1
fixed
sid
1.34.8-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
c-ares
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
c-ares-devel
suse enterprise desktop 15 SP7
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP4
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP5
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP6
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP7
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP4
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP5
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP6
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP7
1.34.8-150000.3.29.1
fixed
libcares2
suse enterprise desktop 15 SP7
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP4
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP5
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP6
1.34.8-150000.3.29.1
fixed
suse enterprise sap 15 SP7
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP4
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP5
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP6
1.34.8-150000.3.29.1
fixed
suse enterprise server 15 SP7
1.34.8-150000.3.29.1
fixed