A library that performs asynchronous DNS operations
Go to file
RHEL Packaging Agent 6bdf9b6170 Fix CVE-2026-33630: double-free in process_timeouts() in c-ares
Backport upstream commit d823199b688052dcdc1646f2ab4cb8c16b1c644a
to fix CVE-2026-33630, a double-free vulnerability in
process_timeouts() in c-ares 1.34.6. The patch also consolidates
requeue handling in ares_process.c to prevent unbounded recursion.
A new patch (c-ares-1.34.6-CVE-2026-33630.patch) was added as
Patch1 in the spec file.

CVE: CVE-2026-33630
Upstream patches:
 - d823199b68.patch
Resolves: RHEL-192867

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-07-22 11:26:29 +02:00
.gitignore Update to 1.34.6 2025-12-09 11:13:03 +01:00
c-ares-1.34.6-CVE-2026-33630.patch Fix CVE-2026-33630: double-free in process_timeouts() in c-ares 2026-07-22 11:26:29 +02:00
c-ares-config.cmake.in update to 1.17.0 2020-11-17 10:54:33 -05:00
c-ares.spec Fix CVE-2026-33630: double-free in process_timeouts() in c-ares 2026-07-22 11:26:29 +02:00
gating.yaml Add gating for c-ares on c10s. 2024-03-25 15:58:45 +01:00
libcares.pc.cmake update to 1.17.0 2020-11-17 10:54:33 -05:00
LICENSE license text 2005-09-05 02:55:40 +00:00
sources Update to 1.34.6 2025-12-09 11:13:03 +01:00