Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 07/07/2026 (07/07/2026, 10:32:19 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: c-ares: * c-ares-1.34.7-1.hum1 (aarch64, x86_64) * c-ares-devel-1.34.7-1.hum1 (aarch64, x86_64) * c-ares-1.34.7-1.hum1.src (src)

Affected software

Affected versions
<1.34.7Red HatRed Hat Hardened Imagesaarch64c-ares-main@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:38:19 UTC

Technical Analysis

CVE-2026-33630 is a use-after-free and double-free vulnerability in the c-ares library's query-completion handling. The flaw arises when a query callback is invoked while the query is still linked in internal lookup structures. An attacker can exploit this remotely via ares_getaddrinfo() over TCP by sending a sequence of crafted DNS responses that force an EDNS-downgrade retry followed by a TCP connection reset. This causes the internal completion handler to access freed memory, resulting in memory corruption and a crash (denial of service). The vulnerability affects all c-ares versions prior to 1.34.7 and is addressed by updating to c-ares 1.34.7 or later. Partial mitigations include using trusted DNS resolvers over trusted transports such as DNS-over-TLS and avoiding calling ares_cancel() from within query callbacks.

Potential Impact

The vulnerability allows remote attackers to cause memory corruption leading to application crashes (denial of service) by sending specially crafted DNS responses. Depending on the allocator and build configuration, there is potential for further impact such as arbitrary code execution. The flaw is remotely exploitable without user interaction or application cooperation. No confidentiality or integrity impacts are explicitly confirmed by the vendor advisory.

Mitigation Recommendations

A fix is available in c-ares version 1.34.7, which is included in the Red Hat Hardened Images RPM update. Users should upgrade to c-ares 1.34.7 or later to fully remediate the vulnerability. Partial mitigations include using trusted DNS resolvers accessed over trusted transports like DNS-over-TLS and avoiding calling ares_cancel() from within query callbacks. There is no complete mitigation for the remotely triggered attack path other than applying the update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:36192
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a58ff2e68715ace43494bbc

Added to database: 07/16/2026, 15:56:30 UTC

Last enriched: 08/16/2026, 17:38:19 UTC

Last updated: 08/27/2026, 10:35:27 UTC

Views: 43

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses