Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Fedora 43 c-ares Critical Use-After-Free Bug Fix FEDORA-2026-d70d93fcd7

fedora
Calendar Grey July 20, 2026
Scroller Fedora
The c-ares library on Fedora 43 received an important update to fix API compatibility and multiple vulnerabilities.
1.34.7 accidentally broke the API compatibility, this is fixed in 1.34.8

Summary

c-ares is a C library that performs DNS requests and name resolves

asynchronously. c-ares is a fork of the library named 'ares', written

by Greg Hudson at MIT.

Update Information:

1.34.7 accidentally broke the API compatibility, this is fixed in 1.34.8. update to 1.34.7 fixes CVE-2026-33630 (GHSA-6wfj-rwm7-3542) and GHSA-pjmc-gx33-gc76 and GHSA- jv8r-gqr9-68wj

Change Log

* Wed Jul 8 2026 Tom Callaway - 1.34.8-1 - update to 1.34.8 * Mon Jul 6 2026 Tom Callaway - 1.34.7-1 - update to 1.34.7 - fixes CVE-2026-33630 (GHSA-6wfj-rwm7-3542) and GHSA-pjmc-gx33-gc76 and GHSA-jv8r-gqr9-68wj * Fri Jan 16 2026 Fedora Release Engineering - 1.34.6-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jan 16 2026 Fedora Release Engineering - 1.34.6-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Dec 17 2025 Tom Callaway - 1.34.6-1 - update to 1.34.6 - fixes CVE-2025-62408 (among other fixes)

References


[ 1 ] Bug #2420051 - c-ares-1.34.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2420051 [ 2 ] Bug #2497696 - CVE-2026-33630 c-ares: c-ares: Use-after-free / double-free in query-completion handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497696 [ 3 ] Bug #2497764 - c-ares-1.34.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2497764

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d70d93fcd7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: c-ares
Product: Fedora 43
Version: 1.34.8
Release: 1.fc43
Summary: A library that performs asynchronous DNS operations

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.