Debian Package Tracker
Register | Log in
Subscribe

c-ares

Choose email to subscribe with

general
  • source: c-ares (main)
  • version: 1.34.8-1
  • maintainer: Gregor Jasny (DMD) (DM)
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.17.1-1+deb11u3
  • o-o-sec: 1.17.1-1+deb11u3
  • oldstable: 1.18.1-3
  • stable: 1.34.5-1+deb13u1
  • stable-sec: 1.34.5-1+deb13u1
  • testing: 1.34.8-1
  • unstable: 1.34.8-1
versioned links
  • 1.17.1-1+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.18.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.34.5-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.34.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libc-ares-dev
  • libc-ares2
  • libcares2
action needed
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2026-33630: (needs triaging) c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.
  • CVE-2026-69184: (needs triaging) c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing a long descending pointer chain and many resource records whose NAME or RDATA fields refer to the chain, causing repeated decompression work that grows quadratically with message size. A single crafted response can stall the single-threaded c-ares event loop and deny DNS resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.
  • CVE-2026-69186: (needs triaging) c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-07 Last update: 2026-09-19 07:02
news
[rss feed]
  • [2026-07-10] c-ares 1.34.8-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-07] Accepted c-ares 1.34.8-1 (source) into unstable (Gregor Jasny)
  • [2026-07-06] Accepted c-ares 1.34.7-1 (source) into unstable (Gregor Jasny)
  • [2025-12-20] Accepted c-ares 1.34.5-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-12-18] Accepted c-ares 1.34.5-1+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-12-12] c-ares 1.34.6-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-08] Accepted c-ares 1.34.6-1 (source) into unstable (Gregor Jasny)
  • [2025-04-11] c-ares 1.34.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-08] Accepted c-ares 1.34.5-1 (source) into unstable (Gregor Jasny)
  • [2025-01-05] c-ares 1.34.4-2.1 MIGRATED to testing (Debian testing watch)
  • [2024-12-31] Accepted c-ares 1.34.4-2.1 (source) into unstable (Boyuan Yang)
  • [2024-12-30] Accepted c-ares 1.34.4-2 (source amd64 all) into unstable (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2024-12-20] c-ares 1.34.4-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-14] Accepted c-ares 1.34.4-1 (source) into unstable (Gregor Jasny)
  • [2024-12-13] c-ares 1.34.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-07] Accepted c-ares 1.34.3-1 (source) into unstable (Gregor Jasny)
  • [2024-10-23] c-ares 1.34.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-17] Accepted c-ares 1.34.2-1 (source) into unstable (Gregor Jasny)
  • [2024-09-27] c-ares 1.33.1-2 MIGRATED to testing (Debian testing watch)
  • [2024-09-21] Accepted c-ares 1.33.1-2 (source) into unstable (Gregor Jasny)
  • [2024-08-29] c-ares 1.33.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-24] Accepted c-ares 1.33.1-1 (source) into unstable (Gregor Jasny)
  • [2024-08-08] c-ares 1.33.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-02] Accepted c-ares 1.33.0-1 (source) into unstable (Gregor Jasny)
  • [2024-07-30] c-ares 1.32.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-07-24] Accepted c-ares 1.32.3-1 (source) into unstable (Gregor Jasny)
  • [2024-07-24] c-ares 1.32.2-2 MIGRATED to testing (Debian testing watch)
  • [2024-07-18] Accepted c-ares 1.32.2-2 (source) into unstable (Gregor Jasny)
  • [2024-07-17] Accepted c-ares 1.32.2-1 (source) into unstable (Gregor Jasny)
  • [2024-06-24] c-ares 1.31.0-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.34.8-1
  • 4 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing