Use After Free Affecting c-ares package, versions [,1.34.8)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Use After Free vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-CONAN-CARES-17906448
  • published9 Jul 2026
  • disclosed7 Jul 2026
  • creditUnknown

Introduced: 7 Jul 2026

CVE-2026-33630  (opens in a new tab)
CWE-416  (opens in a new tab)

How to fix?

Upgrade c-ares to version 1.34.8 or higher.

Overview

Affected versions of this package are vulnerable to Use After Free in the query completion process. An attacker can cause memory corruption and application crash by sending crafted DNS responses that manipulate the sequence of query completions, such as forcing an EDNS-downgrade retry and a connection reset, leading to access of freed memory. This is only exploitable if a malicious or on-path DNS server can interact with the client and force it to use TCP by setting the truncation (TC) bit in a UDP response.

Workaround

This vulnerability can be mitigated by using trusted DNS resolvers over a trusted transport (e.g., DNS-over-TLS) and avoiding calls to ares_cancel() from within a query callback.

CVSS Base Scores

version 4.0
version 3.1