{"id":"AZL-103457","summary":"CVE-2026-69184 affecting package fluent-bit 3.1.10-7","details":"c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing a long descending pointer chain and many resource records whose NAME or RDATA fields refer to the chain, causing repeated decompression work that grows quadratically with message size. A single crafted response can stall the single-threaded c-ares event loop and deny DNS resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.","modified":"2026-09-28T05:39:54Z","published":"2026-09-18T18:17:11Z","upstream":["CVE-2026-69184"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69184"}],"affected":[{"package":{"name":"fluent-bit","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/fluent-bit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.1.10-7"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103457.json"}}],"schema_version":"1.9.0"}