Back to Database
Status published
Medium
CVE-2025-62408
c-ares has a Use After Free vulnerability when connection is cleaned up after error
Vulnerability Description
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62408
Credits & Attribution
No credits recorded in the NVD database.
References
More from c-ares
View All →CVE-2025-31498
c-ares has a use-after-free in read_answers()
High
8.3
CVE-2024-25629
c-ares out of bounds read in ares__read_line()
Medium
4.4
CVE-2023-32067
0-byte UDP payload DoS in c-ares
High
7.5
CVE-2023-31147
Insufficient randomness in generation of DNS query IDs in c-ares
Medium
5.9
CVE-2023-31130
Buffer Underwrite in ares_inet_net_pton()
Medium
4.1
Affected Vendor
c-ares
View all reports →Affected Software
c-ares
Vulnerable Versions:
> 1.32.3, < 1.34.6
Timeline
Official Publish:
December 8th, 2025
Last Modified:
December 9th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H