Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: c-ares: * c-ares-1.34.6-3.1.hum1 (aarch64, x86_64) * c-ares-devel-1.34.6-3.1.hum1 (aarch64, x86_64) * c-ares-1.34.6-3.1.hum1.src (src)
AI Analysis
Technical Summary
CVE-2025-62408 is a use-after-free vulnerability in the c-ares asynchronous DNS resolver library, affecting Red Hat Hardened Images. The flaw occurs when a DNS query terminates after maximum attempts, causing the read_answer() and process_answer() functions to trigger a Denial of Service by crashing the process. This vulnerability is tracked as CWE-416. Red Hat classifies the severity as moderate with a CVSS v3 base score of 5.9, primarily due to high impact on availability. No patch or effective mitigation currently meets Red Hat's standards for deployment and stability. The advisory references a GitHub commit addressing the issue upstream but does not confirm a vendor patch. The vulnerability affects asynchronous DNS resolution in applications using c-ares, potentially causing service disruption.
Potential Impact
The vulnerability causes a Denial of Service by crashing processes that use the c-ares library for asynchronous DNS resolution when queries terminate after maximum retry attempts. This can disrupt applications relying on c-ares, impacting availability. There is no reported impact on confidentiality or integrity. No known exploits are in the wild. The flaw is due to use-after-free conditions that may corrupt memory leading to process crashes.
Mitigation Recommendations
Currently, no mitigation is available or meets Red Hat's criteria for ease of use, applicability, and stability. Users should monitor Red Hat advisories for updates on patches or mitigations. Upgrading to a fixed version when available is recommended. Customers with Red Hat Technical Account Managers can seek direct guidance. No immediate workaround is provided by Red Hat.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: c-ares: * c-ares-1.34.6-3.1.hum1 (aarch64, x86_64) * c-ares-devel-1.34.6-3.1.hum1 (aarch64, x86_64) * c-ares-1.34.6-3.1.hum1.src (src)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-62408 is a use-after-free vulnerability in the c-ares asynchronous DNS resolver library, affecting Red Hat Hardened Images. The flaw occurs when a DNS query terminates after maximum attempts, causing the read_answer() and process_answer() functions to trigger a Denial of Service by crashing the process. This vulnerability is tracked as CWE-416. Red Hat classifies the severity as moderate with a CVSS v3 base score of 5.9, primarily due to high impact on availability. No patch or effective mitigation currently meets Red Hat's standards for deployment and stability. The advisory references a GitHub commit addressing the issue upstream but does not confirm a vendor patch. The vulnerability affects asynchronous DNS resolution in applications using c-ares, potentially causing service disruption.
Potential Impact
The vulnerability causes a Denial of Service by crashing processes that use the c-ares library for asynchronous DNS resolution when queries terminate after maximum retry attempts. This can disrupt applications relying on c-ares, impacting availability. There is no reported impact on confidentiality or integrity. No known exploits are in the wild. The flaw is due to use-after-free conditions that may corrupt memory leading to process crashes.
Mitigation Recommendations
Currently, no mitigation is available or meets Red Hat's criteria for ease of use, applicability, and stability. Users should monitor Red Hat advisories for updates on patches or mitigations. Upgrading to a fixed version when available is recommended. Customers with Red Hat Technical Account Managers can seek direct guidance. No immediate workaround is provided by Red Hat.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:7414
- Cve Count
- 1
Threat ID: 6a4049d427e9c7971982cabc
Added to database: 06/27/2026, 22:08:20 UTC
Last enriched: 08/16/2026, 18:06:51 UTC
Last updated: 09/12/2026, 22:01:30 UTC
Views: 32
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.