Impact
A malicious DNS responder can forge record counts (ANCOUNT, NSCOUNT, ARCOUNT) to trick the c-ares resolver into allocating huge arrays before any validation of message contents. This uncontrolled memory use can repeatedly increase and release heap space, exhausting system resources and causing name resolution to fail. The weakness is a classic resource exhaustion flaw described by CWE-400 and involves improper initialization of memory allocation (CWE-1284).
Affected Systems
Any software that links to the c-ares resolver library older than version 1.34.7 is vulnerable. The issue was fixed in release 1.34.7 of c-ares; applications using older versions of the library need to be updated.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity for this denial-of-service vulnerability. The EPSS score of 0.524% suggests a small but nonzero likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. It exploits resource exhaustion (CWE-400) and improper initialization of memory allocation (CWE-1284). Exploitation requires an attacker who can send crafted DNS responses to the vulnerable resolver—typically through a malicious or compromised authoritative server or by using forged packets. Repeated exploitation can degrade system performance or deny service to clients that depend on name resolution.
OpenCVE Enrichment