Use-after-free in c-ares - CVE-2025-31498

 

Use-after-free in c-ares - CVE-2025-31498

Published: April 8, 2025


Vulnerability identifier: #VU107155
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31498
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the read_answers() function. A remote attacker can send specially crafted ICMP UNREACHABLE packets to the application, trigger a use-after-free error and execute arbitrary code on the system.



Affected software

c-ares
Rapid Infrastructure Automation
IBM Cloud Pak for Watson AIOps
Netcool Operations Insight
watsonx.data
Nessus Network Monitor
IBM DataPower Gateway
IBM Cloud Pak for Multicloud Management
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
Fedora
IBM API Connect
libcares2 (Ubuntu package)
c-ares
npm
nodejs-full-i18n
nodejs
nodejs-docs
nodejs-devel
nodejs22
nodejs-packaging-bundler
nodejs-packaging
IBM App Connect Enterprise

How to mitigate CVE-2025-31498

Install updates from vendor's website.

c-ares - update to 1.34.5
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.3.1
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Nessus Network Monitor - update to 6.5.3
IBM API Connect - update to 10.0.8.2 ifix2
IBM DataPower Gateway - addressed in versions 10.5.0.19, 10.6.0.7, 10.6.5.0
libcares2 (Ubuntu package) - addressed in versions 1.33.0-1ubuntu0.1, 1.34.4-2.1ubuntu0.1
c-ares - addressed in versions 1.34.5-1.fc40, 1.34.5-1.fc41, 1.34.5-1.fc42
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
npm - update to 10.8.2-1.20.19.1.1
IBM App Connect Enterprise - addressed in versions 12.0.13, 12.13.0
nodejs-full-i18n - update to 20.19.1-1
nodejs - update to 20.19.1-1
nodejs-docs - update to 20.19.1-1
nodejs-devel - update to 20.19.1-1
nodejs22 - addressed in versions 22.15.0-2.fc40, 22.15.0-2.fc41, 22.15.0-2.fc42
nodejs-packaging-bundler - update to 2021.06-4
nodejs-packaging - update to 2021.06-4

External References

Related Security Bulletins