CVE-2025-62408: c-ares has a Use After Free vulnerability when connection is cleaned up after error
c-ares has a Use After Free vulnerability when connection is cleaned up after error
Other sources
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using readanswer() and processanswer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62408?
CVE-2025-62408 has a severity that is classified as a Denial of Service vulnerability.
How do I fix CVE-2025-62408?
To fix CVE-2025-62408, upgrade c-ares to version 1.34.6 or later.
What software versions are affected by CVE-2025-62408?
CVE-2025-62408 affects c-ares versions from 1.32.3 through 1.34.5.
What types of attacks can CVE-2025-62408 lead to?
CVE-2025-62408 can lead to Denial of Service attacks due to the termination of a query after maximum attempts.
Is CVE-2025-62408 a critical vulnerability?
While CVE-2025-62408 is significant, it is primarily a Denial of Service vulnerability, not classified as critical.