
Open Source Security mailing list@oss_security
Patch
c-ares 1.34.7 fixes 3 vulns https://www.openwall.com/lists/oss-security/2026/07/06/8 CVE-2026-33630: Use-after-free / double-free in query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP GHSA-pjmc-gx33-gc76: CPU-exhaustion DoS GHSA-jv8r-gqr9-68wj: Memory-amplification DoS
Post summary
The post announces that c-ares 1.34.7 includes patches for three CVEs—one use‑after‑free and two DoS vulnerabilities—without indicating active exploitation or providing PoC or exploit code.
01031639
4.7K followersView on X
