USN-7477-1: c-ares vulnerability
Published May 5, 2025
·Updated
It was discovered that c-ares incorrectly handled re-enqueuing certain queries. A remote attacker could possibly use this issue to cause c-ares to crash, resulting in a denial of service.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/libcares2<1.34.4-2.1ubuntu0.1
1.34.4-2.1ubuntu0.1
Ubuntu Ubuntu=25.04
All of the following
ubuntu/libcares2<1.33.0-1ubuntu0.1
1.33.0-1ubuntu0.1
Ubuntu Ubuntu=24.10
Event History
May 5, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7477-1?
The severity of USN-7477-1 is classified as a denial of service vulnerability, which could lead to application crashes.
2
How do I fix USN-7477-1?
To fix USN-7477-1, update to the patched versions of libcares2: 1.34.4-2.1ubuntu0.1 for Ubuntu 25.04 or 1.33.0-1ubuntu0.1 for Ubuntu 24.10.
3
Which versions of libcares2 are affected by USN-7477-1?
USN-7477-1 affects libcares2 versions prior to 1.34.4-2.1ubuntu0.1 for Ubuntu 25.04 and 1.33.0-1ubuntu0.1 for Ubuntu 24.10.
4
What products are impacted by USN-7477-1?
USN-7477-1 impacts Ubuntu products, specifically versions 25.04 and 24.10 using the libcares2 package.
5
Can USN-7477-1 be exploited remotely?
Yes, USN-7477-1 can be exploited by a remote attacker to cause c-ares to crash.