Description
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory amplification
Action: Patch
AI Analysis

Impact

A malicious DNS responder can forge record counts (ANCOUNT, NSCOUNT, ARCOUNT) to trick the c-ares resolver into allocating huge arrays before any validation of message contents. This uncontrolled memory use can repeatedly increase and release heap space, exhausting system resources and causing name resolution to fail. The weakness is a classic resource exhaustion flaw described by CWE-400 and involves improper initialization of memory allocation (CWE-1284).

Affected Systems

Any software that links to the c-ares resolver library older than version 1.34.7 is vulnerable. The issue was fixed in release 1.34.7 of c-ares; applications using older versions of the library need to be updated.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity for this denial-of-service vulnerability. The EPSS score of 0.524% suggests a small but nonzero likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. It exploits resource exhaustion (CWE-400) and improper initialization of memory allocation (CWE-1284). Exploitation requires an attacker who can send crafted DNS responses to the vulnerable resolver—typically through a malicious or compromised authoritative server or by using forged packets. Repeated exploitation can degrade system performance or deny service to clients that depend on name resolution.

Generated by OpenCVE AI on September 23, 2026 at 01:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade c-ares to version 1.34.7 or later, ensuring all dependent binaries are recompiled against the patched library
  • Replace any custom DNS resolver logic with the updated library to guarantee validation of record counts before memory allocation
  • Restrict outgoing DNS queries to trusted resolvers and block traffic from untrusted or malicious servers to mitigate exposure to forged DNS responses

Generated by OpenCVE AI on September 23, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1284
References
Metrics threat_severity

None

threat_severity

Important


Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared C-ares
C-ares c-ares
Vendors & Products C-ares
C-ares c-ares

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.
Title c-ares: Memory-amplification denial of service via unvalidated DNS header record counts
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T19:51:33.881Z

Reserved: 2026-08-03T16:00:23.482Z

Link: CVE-2026-69186

cve-icon Vulnrichment

Updated: 2026-09-18T19:51:29.176Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:17:11.637

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-69186

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T17:25:42Z

Links: CVE-2026-69186 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:00:10Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-400

    Uncontrolled Resource Consumption