{"id":"USN-8844-1","summary":"c-ares vulnerability","details":"It was discovered that c-ares incorrectly handled certain query completion\ncallbacks. An attacker could possibly use this issue to trigger a use-\nafter-free or double-free, resulting in a denial of service or arbitrary\ncode execution.","modified":"2026-09-29T23:56:46.796447528Z","published":"2026-09-29T15:15:25Z","related":["UBUNTU-CVE-2026-33630"],"upstream":["CVE-2026-33630","UBUNTU-CVE-2026-33630"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8844-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-33630"}],"affected":[{"package":{"name":"c-ares","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/c-ares?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.34.6-1ubuntu0.1"}]}],"versions":["1.34.5-1","1.34.6-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1.34.6-1ubuntu0.1","binary_name":"libc-ares2"},{"binary_name":"libcares2","binary_version":"1.34.6-1ubuntu0.1"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:26.04:LTS","cves":[{"id":"CVE-2026-33630","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8844-1.json"}}],"schema_version":"1.9.0"}