gpp_maybe
Security update for c-ares
SUSE-SLE-Micro-5.3-2026-4021
This update for c-ares fixes the following issues: - CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279). - CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955). - CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). - CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416). - CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). - CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: - updated to 1.36.8.
-
Release DateSep 7 2026
-
ReferencesBugzilla: 1220279, 1240955, 1254738, 1270416, 1276290, 1276291
CVEs: CVE-2024-25629, CVE-2025-31498, CVE-2025-62408, CVE-2026-33630, CVE-2026-69184, CVE-2026-69186 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Micro 5.3 s390x
-
Packages
SUSE Linux Enterprise Micro 5.3 aarch64
-
Packages
SUSE Linux Enterprise Micro 5.3 x86_64
-
Packages