Updated c-ares packages fix security vulnerabilities
Publication date: 31 Aug 2026Modification date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33630 , CVE-2026-69184 , CVE-2026-69186
Description
Use-after-free / double-free in c-ares query-completion handling,
remotely triggerable via ares_getaddrinfo() over TCP. (CVE-2026-33630)
CPU-exhaustion denial of service via unbounded DNS name compression
pointer chains. (CVE-2026-69184)
Memory-amplification denial of service via unvalidated DNS header record
counts. (CVE-2026-69186)
References
- https://bugs.mageia.org/show_bug.cgi?id=35847
- https://www.openwall.com/lists/oss-security/2026/07/06/8
- https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542
- https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76
- https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RP4OX63ZTYCCB4UK6HI4BFEPQEPSNLOJ/
- https://www.cve.org/CVERecord?id=CVE-2026-33630
- https://www.cve.org/CVERecord?id=CVE-2026-69184
- https://www.cve.org/CVERecord?id=CVE-2026-69186
SRPMS
10/core
- c-ares-1.34.8-1.mga10