<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T00:01:12.654495+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-69186</id>
    <title>BELL-CVE-2026-69186</title>
    <updated>2026-10-06T00:01:12.773965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: c-ares, Alpaquita:stream: c-ares, BellSoft Hardened Containers:25: c-ares, BellSoft Hardened Containers:stream: c-ares</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-69186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372380</id>
    <title>EUVD-2026-372380</title>
    <updated>2026-10-06T00:01:12.774020+00:00</updated>
    <content>EUVD-2026-372380</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69186</id>
    <title>fkie_cve-2026-69186</title>
    <updated>2026-10-06T00:01:12.774035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-69186</id>
    <title>msrc_CVE-2026-69186 — c-ares: Memory-amplification denial of service via unvalidated DNS header record counts</title>
    <updated>2026-10-06T00:01:12.774062+00:00</updated>
    <content>msrc_CVE-2026-69186</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-69186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11593-1</id>
    <title>openSUSE-SU-2026:11593-1 — c-ares-devel-1.34.8-1.1 on GA media</title>
    <updated>2026-10-06T00:01:12.774079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>c-ares-devel-1.34.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11593-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:40574</id>
    <title>RHSA-2026:40574 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-06T00:01:12.774097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>c-ares: c-ares: CPU exhaustion denial of service via unbounded DNS name compression pointer chains c-ares: c-ares: Denial of Service via unvalidated DNS header record counts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:40574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23364-1</id>
    <title>SUSE-SU-2026:23364-1 — Security update for c-ares</title>
    <updated>2026-10-06T00:01:12.774114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for c-ares</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23364-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69186</id>
    <title>UBUNTU-CVE-2026-69186</title>
    <updated>2026-10-06T00:01:12.774129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: c-ares, Ubuntu:Pro:18.04:LTS: c-ares, Ubuntu:20.04:LTS: c-ares, Ubuntu:22.04:LTS: c-ares, Ubuntu:24.04:LTS: c-ares, Ubuntu:26.04:LTS: c-ares</p>
<p>c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69186"/>
  </entry>
</feed>
