PT-2025-15436 · C-Ares+5 · C-Ares+5

CVE-2025-31498

·

Published

2025-04-08

·

Updated

2026-08-28

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions c-ares versions 1.32.3 through 1.34.4 Node.js versions prior to 22.15.0
Description A use-after-free vulnerability exists in the read answers() function of c-ares, a library used for asynchronous DNS resolution. This occurs when process answer() may re-enqueue a query due to a DNS Cookie Failure or if the upstream server does not properly support EDNS, or potentially on TCP queries if the remote connection is closed immediately after a response. If an issue occurs while attempting to place the new transaction on the wire, the connection handle is closed, but read answers() still expects it to be available. A remote attacker could potentially exploit this by flooding the target with ICMP UNREACHABLE packets if they control the upstream nameserver, or a local attacker could manipulate system behavior to cause send() or write() to return a failure condition. This vulnerability is addressed in c-ares version 1.34.5.
Recommendations Update c-ares to version 1.34.5 or later. Update Node.js to version 22.15.0 or later.

Exploit

Fix

DoS

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:4459
ALSA-2025:4461
ALSA-2025:7426
ALSA-2025:7433
ALSA-2025:7502
AZL-59742
BDU:2025-04858
CESA-2025_4459
CESA-2025_4461
CVE-2025-31498
ECHO-6BDE-78E8-D894
GHSA-6HXC-62JH-P29V
INFSA-2025_4459
INFSA-2025_4461
INFSA-2025_7426
INFSA-2025_7433
OPENSUSE-SU-2025:14977-1
RHSA-2025:4459
RHSA-2025:4461
RHSA-2025:7426
RHSA-2025:7433
RHSA-2025:7502
RHSA-2025:7537
RHSA-2025_4459
RHSA-2025_4461
RHSA-2025_7426
RHSA-2025_7433
SUSE-SU-2026:23364-1
USN-7477-1

Affected Products

Almalinux
Centos
Red Hat
Rocky Linux
Ubuntu
C-Ares