Skip to content
openSUSE c-ares Important DoS Threats Vulnerabilities 2026-21721

openSUSE c-ares Important DoS Threats Vulnerabilities 2026-21721

Linuxsecurity •LinuxSecurity Advisories • September 2, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

This update for c-ares fixes the following issues:

Updat to c-ares 1.36.8.

- CVE-2026-33630: remotely triggerable use-after-free/double-free in query-completion handling via `ares_getaddrinfo()`

over TCP (bsc#1270416).

- CVE-2026-69184: CPU exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290).

- CVE-2026-69186: memory amplification denial of service via unvalidated DNS header record counts (bsc#1276291).

- For details, see

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

zypper in -t patch openSUSE-Leap-16.0-1579=1

- openSUSE Leap 16.0:

c-ares-devel-1.34.8-160000.1.1

c-ares-utils-1.34.8-160000.1.1

libcares2-1.34.8-160000.1.1

*

*

*

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

CWE Weaknesses (1)

Platforms (1)