﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
23565	c-ares-1.34.7	Joe Locash	SecurityAdvisory	"{{{
c-ares version 1.34.7 - July 6 2026

This is a security release.

Security:

    CVE-2026-33630. Use-after-free / double-free in c-ares' query-completion
    handling, remotely triggerable via ares_getaddrinfo() over TCP. Please see
    GHSA-6wfj-rwm7-3542
    CPU-exhaustion denial of service via unbounded DNS name compression pointer
    chains. Please see
    GHSA-pjmc-gx33-gc76
    Memory-amplification denial of service via unvalidated DNS header record
    counts. Please see
    GHSA-jv8r-gqr9-68wj

Changes:

    ares_getaddrinfo(): handle a NULL node per POSIX and implement
    ARES_AI_PASSIVE. PR #1186
    Mark parameters in callbacks as const.
    PR #1060
    Correct ARES_CLASS_HESOID misspelling to ARES_CLASS_HESIOD.
    PR #1092

Bugfixes:

    Fix sticky server recovery when all servers have failures. PR #1192
    Fix UDP socket exhaustion regression: retire connections per-connection, not via server failure count. PR #1197
    Guard DNS record binary length overflow. PR #1168
    Prevent integer overflow in allocation size calculations. PR #1147
    Prevent overflow in ares_array allocation size calculations. PR #1117
    Prevent integer overflow in buffer size calculation. PR #1116
    Add overflow checks to ares_buf_ensure_space(). PR #1094
    Skip name compression offsets beyond the 14-bit pointer limit. PR #1159
    ares_dns_parse: reject name compression in RDATA where not permitted (RFC 3597). PR #1190
    ares_dns_parse: reject responses with more than one OPT record (RFC 6891). PR #1189
    Discard oversized UDP datagrams instead of truncating the length frame. PR #1161
    Route numeric config parsing through range-checked ares_str_parse_uint. PR #1158
    Replace atoi-based port parsing with validated helper. PR #1097
    Defer TCP connection error handling until DNS responses are parsed. PR #1138
    Prevent undefined-behavior left shift in ares_calc_query_timeout(). PR #1151
    Use unsigned type for ares_round_up_pow2_u64 to avoid undefined behavior. PR #1107
    Fix undefined behavior in ares_buf_replace() pointer arithmetic. PR #1099
    ares_array: reset offset when array becomes empty. PR #1165
    ares_iface_ips: add ARES_IFACE_IP_NONE zero enum value. PR #1187
    ares_sysconfig_files: recognize AIX netsvc.conf bind4/local4 tokens. PR #1188
    Use safe string construction in Windows sysconfig join path. PR #1143
    Fix zero-length RAW_RR losing type metadata during parsing. PR #1129
    Fix RAW_RR type tostr/fromstr roundtrip mismatch. PR #1123
    Fix NULL dereference for ifa netmask. PR #1120
    adig: fix negated option prefix parsing. PR #1135
    Use UnregisterWaitEx to prevent use-after-free on Win32. PR #1111
    Add NULL check after ares_malloc_zero in Windows UTF8 conversion. PR #1121
    Fix NULL dereference after ares_malloc_zero in Win32 IOCP event add. PR #1132
    Fix microsecond overflow in ares_queue_wait_empty timeout. PR #1122
    Fix NULL dereference in ares_buf_replace() on NULL buf. PR #1124
    Initialize *read_bytes in ares_socket_recvfrom(). PR #1125
    Fix memory leak of binbuf in ares_buf_parse_dns_binstr_int. PR #1126
    Fix memory leak of qcache entry on key allocation failure. PR #1127
    Fix memory leak of buf in ares_dns_multistring_combined() on OOM. PR #1110
    Fix memory leaks on error paths in two functions. PR #1109
    Fix memory leak of buckets in ares_htable_dict_keys() error path. PR #1108
    Fix memory leak of bucket->key in ares_htable_dict_insert error path. PR #1105
    Fix additional memory leaks. PR #1091 PR #1078
    Prevent corrupt addrinfo nodes on sockaddr allocation failure. PR #1112
    Fix two logic bugs in DNS cookie handling. PR #1103
    Fix linked list INSERT_BEFORE corruption and array insertdata_first ordering. PR #1101
    Fix HASH_IDX macro missing parentheses. PR #1128
    Fix malloc(0) in ares_htable_all_buckets on empty table. PR #1131
    Fix wrong sizeof in QNX confstr() call truncating domain names. PR #1130
    Clear probe pending flag after timeout. PR #1059
    Fix incorrect check for empty wide string. PR #1064
    Handle strdup failure. PR #1077
    doc: reference ares_free_string(), not ares_free(). PR #1084
}}}"	enhancement	closed	high	98-Security	BOOK	git	medium	fixed		
