AZL-103307

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103307.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-103307
Upstream
Published
2026-09-18T18:17:11Z
Modified
2026-09-20T05:33:47Z
Summary
CVE-2026-69184 affecting package c-ares 1.30.0-2
Details

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing a long descending pointer chain and many resource records whose NAME or RDATA fields refer to the chain, causing repeated decompression work that grows quadratically with message size. A single crafted response can stall the single-threaded c-ares event loop and deny DNS resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.

References

Affected packages

Azure Linux:3 / c-ares

Package

Name
c-ares
Purl
pkg:rpm/azure-linux/c-ares

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.30.0-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103307.json"