First published: Mon May 05 2025(Updated: )
It was discovered that c-ares incorrectly handled re-enqueuing certain queries. A remote attacker could possibly use this issue to cause c-ares to crash, resulting in a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libcares2 | <1.34.4-2.1ubuntu0.1 | 1.34.4-2.1ubuntu0.1 |
Ubuntu | =25.04 | |
All of | ||
ubuntu/libcares2 | <1.33.0-1ubuntu0.1 | 1.33.0-1ubuntu0.1 |
Ubuntu | =24.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7477-1 is classified as a denial of service vulnerability, which could lead to application crashes.
To fix USN-7477-1, update to the patched versions of libcares2: 1.34.4-2.1ubuntu0.1 for Ubuntu 25.04 or 1.33.0-1ubuntu0.1 for Ubuntu 24.10.
USN-7477-1 affects libcares2 versions prior to 1.34.4-2.1ubuntu0.1 for Ubuntu 25.04 and 1.33.0-1ubuntu0.1 for Ubuntu 24.10.
USN-7477-1 impacts Ubuntu products, specifically versions 25.04 and 24.10 using the libcares2 package.
Yes, USN-7477-1 can be exploited by a remote attacker to cause c-ares to crash.