Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: c-ares: * c-ares-1.34.7-1.hum1 (aarch64, x86_64) * c-ares-devel-1.34.7-1.hum1 (aarch64, x86_64) * c-ares-1.34.7-1.hum1.src (src)
AI Analysis
Technical Summary
CVE-2026-33630 is a use-after-free and double-free vulnerability in the c-ares library's query-completion handling. The flaw arises when a query callback is invoked while the query is still linked in internal lookup structures. An attacker can exploit this remotely via ares_getaddrinfo() over TCP by sending a sequence of crafted DNS responses that force an EDNS-downgrade retry followed by a TCP connection reset. This causes the internal completion handler to access freed memory, resulting in memory corruption and a crash (denial of service). The vulnerability affects all c-ares versions prior to 1.34.7 and is addressed by updating to c-ares 1.34.7 or later. Partial mitigations include using trusted DNS resolvers over trusted transports such as DNS-over-TLS and avoiding calling ares_cancel() from within query callbacks.
Potential Impact
The vulnerability allows remote attackers to cause memory corruption leading to application crashes (denial of service) by sending specially crafted DNS responses. Depending on the allocator and build configuration, there is potential for further impact such as arbitrary code execution. The flaw is remotely exploitable without user interaction or application cooperation. No confidentiality or integrity impacts are explicitly confirmed by the vendor advisory.
Mitigation Recommendations
A fix is available in c-ares version 1.34.7, which is included in the Red Hat Hardened Images RPM update. Users should upgrade to c-ares 1.34.7 or later to fully remediate the vulnerability. Partial mitigations include using trusted DNS resolvers accessed over trusted transports like DNS-over-TLS and avoiding calling ares_cancel() from within query callbacks. There is no complete mitigation for the remotely triggered attack path other than applying the update.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: c-ares: * c-ares-1.34.7-1.hum1 (aarch64, x86_64) * c-ares-devel-1.34.7-1.hum1 (aarch64, x86_64) * c-ares-1.34.7-1.hum1.src (src)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-33630 is a use-after-free and double-free vulnerability in the c-ares library's query-completion handling. The flaw arises when a query callback is invoked while the query is still linked in internal lookup structures. An attacker can exploit this remotely via ares_getaddrinfo() over TCP by sending a sequence of crafted DNS responses that force an EDNS-downgrade retry followed by a TCP connection reset. This causes the internal completion handler to access freed memory, resulting in memory corruption and a crash (denial of service). The vulnerability affects all c-ares versions prior to 1.34.7 and is addressed by updating to c-ares 1.34.7 or later. Partial mitigations include using trusted DNS resolvers over trusted transports such as DNS-over-TLS and avoiding calling ares_cancel() from within query callbacks.
Potential Impact
The vulnerability allows remote attackers to cause memory corruption leading to application crashes (denial of service) by sending specially crafted DNS responses. Depending on the allocator and build configuration, there is potential for further impact such as arbitrary code execution. The flaw is remotely exploitable without user interaction or application cooperation. No confidentiality or integrity impacts are explicitly confirmed by the vendor advisory.
Mitigation Recommendations
A fix is available in c-ares version 1.34.7, which is included in the Red Hat Hardened Images RPM update. Users should upgrade to c-ares 1.34.7 or later to fully remediate the vulnerability. Partial mitigations include using trusted DNS resolvers accessed over trusted transports like DNS-over-TLS and avoiding calling ares_cancel() from within query callbacks. There is no complete mitigation for the remotely triggered attack path other than applying the update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:36192
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a58ff2e68715ace43494bbc
Added to database: 07/16/2026, 15:56:30 UTC
Last enriched: 08/16/2026, 17:38:19 UTC
Last updated: 08/27/2026, 10:35:27 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.