Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
c-ares is a C library that performs DNS requests and name resolves
asynchronously. c-ares is a fork of the library named 'ares', written
by Greg Hudson at MIT.
Update Information:
1.34.7 accidentally broke the API compatibility, this is fixed in 1.34.8. update to 1.34.7 fixes CVE-2026-33630 (GHSA-6wfj-rwm7-3542) and GHSA-pjmc-gx33-gc76 and GHSA- jv8r-gqr9-68wj
* Wed Jul 8 2026 Tom Callaway
[ 1 ] Bug #2420051 - c-ares-1.34.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2420051
[ 2 ] Bug #2497696 - CVE-2026-33630 c-ares: c-ares: Use-after-free / double-free in query-completion handling [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2497696
[ 3 ] Bug #2497764 - c-ares-1.34.8 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2497764
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d70d93fcd7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.