Use-after-free in c-ares - CVE-2025-62408

 

Use-after-free in c-ares - CVE-2025-62408

Published: December 8, 2025


Vulnerability identifier: #VU119383
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62408
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a use-after-free error within the read_answer() function when process_answer() terminates a query such as after maximum attempts. A remote attacker can perform a denial of service attack.

Note, the vulnerability exists due to an incomplete fix for #VU107155 (CVE-2025-31498).


Affected software

c-ares
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openSUSE Leap
Ubuntu
watsonx.data
Nessus Network Monitor
c-ares (Ubuntu package)
c-ares (Debian package)
nodejs18-docs
nodejs18-debugsource
nodejs18-debuginfo
nodejs18
npm18
nodejs18-devel
corepack18

How to mitigate CVE-2025-62408

Install updates from vendor's website.

c-ares - update to 1.34.6
watsonx.data - update to 2.3.1
Nessus Network Monitor - update to 6.5.3
c-ares (Ubuntu package) - addressed in versions 1.34.4-2.1ubuntu0.2, 1.34.5-1ubuntu0.1
c-ares (Debian package) - update to 1.34.5-1+deb13u1
nodejs18-docs - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18-debugsource - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18-debuginfo - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18 - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
npm18 - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18-devel - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
corepack18 - update to 18.20.8-150400.9.39.1

External References

Related Security Bulletins