oss-sec mailing list archives

CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free()


From: Brad House <brad () brad-house com>
Date: Mon, 8 Dec 2025 11:42:33 -0500

Moderate.

Use after free() in read_answer() when process_answer() may terminate a query such as after maximum attempts. This was causing the connection to be closed, but still possibly additional answers to be processed. This is a missed case from CVE-2025-31498.

Use after free will lead to crash / Denial of Service.

Patch: https://github.com/c-ares/c-ares/commit/714bf5675c541bd1e668a8db8e67ce012651e618.patch

Links: https://github.com/c-ares/c-ares/security/advisories/GHSA-jq53-42q6-pqr5


Current thread: