Use-after-free in c-ares - CVE-2025-31498
Published: April 8, 2025
Vulnerability identifier: #VU107155
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31498
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the read_answers() function. A remote attacker can send specially crafted ICMP UNREACHABLE packets to the application, trigger a use-after-free error and execute arbitrary code on the system.
Affected software
c-ares
Rapid Infrastructure Automation
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight
watsonx.data
Nessus Network Monitor
IBM DataPower Gateway
IBM Cloud Pak for Multicloud Management
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
Fedora
IBM API Connect
libcares2 (Ubuntu package)
c-ares
npm
nodejs-full-i18n
nodejs
nodejs-docs
nodejs-devel
nodejs22
nodejs-packaging-bundler
nodejs-packaging
IBM App Connect Enterprise
Rapid Infrastructure Automation
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight
watsonx.data
Nessus Network Monitor
IBM DataPower Gateway
IBM Cloud Pak for Multicloud Management
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
Fedora
IBM API Connect
libcares2 (Ubuntu package)
c-ares
npm
nodejs-full-i18n
nodejs
nodejs-docs
nodejs-devel
nodejs22
nodejs-packaging-bundler
nodejs-packaging
IBM App Connect Enterprise
How to mitigate CVE-2025-31498
Install updates from vendor's website.
c-ares - update to 1.34.5
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.3.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Nessus Network Monitor - update to 6.5.3
IBM API Connect - update to 10.0.8.2 ifix2
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7, 10.6.5.0
libcares2 (Ubuntu package) - addressed in versions 1.33.0-1ubuntu0.1, 1.34.4-2.1ubuntu0.1
c-ares - addressed in versions 1.34.5-1.fc40, 1.34.5-1.fc41, 1.34.5-1.fc42
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
npm - update to 10.8.2-1.20.19.1.1
IBM App Connect Enterprise - addressed in versions 12.0.13, 12.13.0
nodejs-full-i18n - update to 20.19.1-1
nodejs - update to 20.19.1-1
nodejs-docs - update to 20.19.1-1
nodejs-devel - update to 20.19.1-1
nodejs22 - addressed in versions 22.15.0-2.fc40, 22.15.0-2.fc41, 22.15.0-2.fc42
nodejs-packaging-bundler - update to 2021.06-4
nodejs-packaging - update to 2021.06-4
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.3.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Nessus Network Monitor - update to 6.5.3
IBM API Connect - update to 10.0.8.2 ifix2
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7, 10.6.5.0
libcares2 (Ubuntu package) - addressed in versions 1.33.0-1ubuntu0.1, 1.34.4-2.1ubuntu0.1
c-ares - addressed in versions 1.34.5-1.fc40, 1.34.5-1.fc41, 1.34.5-1.fc42
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
npm - update to 10.8.2-1.20.19.1.1
IBM App Connect Enterprise - addressed in versions 12.0.13, 12.13.0
nodejs-full-i18n - update to 20.19.1-1
nodejs - update to 20.19.1-1
nodejs-docs - update to 20.19.1-1
nodejs-devel - update to 20.19.1-1
nodejs22 - addressed in versions 22.15.0-2.fc40, 22.15.0-2.fc41, 22.15.0-2.fc42
nodejs-packaging-bundler - update to 2021.06-4
nodejs-packaging - update to 2021.06-4
External References
Related Security Bulletins
- Remote code execution in c-ares
- Fedora 41 update for c-ares
- Fedora 42 update for c-ares
- Fedora 40 update for c-ares
- Fedora 40 update for nodejs22
- Fedora 42 update for nodejs22
- Fedora 41 update for nodejs22
- Red Hat Enterprise Linux 8 update for the nodejs:20 module
- Ubuntu update for c-ares
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Anolis OS update for nodejs:20 module
- Multiple vulnerabilities in IBM Rapid Infrastructure Automation
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM DataPower Gateway
- Tenable Network Monitor update for third-party components
- IBM watsonx.data update for c-ares