Inefficient Algorithmic Complexity in c-ares - CVE-2026-69184
Published: July 7, 2026 / Updated: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in ares_dns_name_parse() when parsing crafted DNS responses with unbounded compression pointer chains. A remote attacker can send a specially crafted DNS response to cause a denial of service.
Because c-ares runs on a single-threaded event loop, parsing a crafted response can stall all resolution for the duration.