Back Linuxsecurity Ubuntu 26.04 LTS c-ares Important DoS and Code Exec CVE-2026
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
c-ares could be made to crash or run programs if it received specially crafted network traffic. Software Description: - c-ares: library for asynchronous name resolution Details: It was discovered that c-ares incorrectly handled certain query completion callbacks. An attacker could possibly use this issue to trigger a use- after-free or double-free, resulting in a denial of service or arbitrary code execution.
c-ares could be made to crash or run programs if it received specially
crafted network traffic.
Software Description:
- c-ares: library for asynchronous name resolution
It was discovered that c-ares incorrectly handled certain query completion
callbacks. An attacker could possibly use this issue to trigger a use-
after-free or double-free, resulting in a denial of service or arbitrary
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libcares2 1.34.6-1ubuntu0.1 In general, a standard system update will make all the necessary changes.
Ubuntu Security Notice USN-8844-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
