https://seclists.org/oss-sec/2025/q2/27: CVE-2025-31498: c-as use-after-fe
Published Apr 8, 2025
·Updated
Affected Software
1 affected component
c-ares c-ares>=1.32.3<1.34.4
Frequently Asked Questions
1
What is the severity of CVE-2025-31498?
CVE-2025-31498 is classified as a high severity use-after-free vulnerability.
2
How do I fix CVE-2025-31498?
To mitigate CVE-2025-31498, upgrade to c-ares version 1.34.5 or later.
3
Which versions of c-ares are affected by CVE-2025-31498?
CVE-2025-31498 affects c-ares versions 1.32.3 to 1.34.4.
4
Is there a workaround for CVE-2025-31498?
There are no known workarounds for CVE-2025-31498.
5
Who reported CVE-2025-31498?
CVE-2025-31498 was reported by Erik Lax.