Skip to content
Critical Vulnerability in c-ares Library Allows DoS and Code Execution

Critical Vulnerability in c-ares Library Allows DoS and Code Execution

First seen 29 Sep 2026, 21:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 21:05 UTC
  • •c-ares library vulnerability could lead to DoS or arbitrary code execution.
  • •Affected systems include Ubuntu 26.04 LTS with specific package versions.
  • •Users are urged to update their systems to mitigate risks.

A vulnerability in the c-ares library, which is used for asynchronous name resolution, has been identified. This flaw allows attackers to exploit specially crafted network traffic, potentially leading to denial of service or arbitrary code execution. The issue arises from improper handling of query completion callbacks, which could result in use-after-free or double-free conditions. Affected systems include Ubuntu 26.04 LTS, specifically the libcares2 package version 1.34.6-1ubuntu0.1. Users are advised to update their systems to mitigate the risk. Both Ubuntu and Linux Security have issued advisories on this matter, highlighting the urgency of applying the necessary patches. The vulnerability has not yet been confirmed as actively exploited in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
Vulnerability disclosed
Ubuntu and Linux Security reported a critical vulnerability in the c-ares library affecting Ubuntu 26.04 LTS.
Ubuntu
2026-09-29
Patch released
Users are advised to update to libcares2 version 1.34.6-1ubuntu0.1 to address the vulnerability.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed