<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:15:20 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-69186</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-69186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: c-ares, Alpaquita:stream: c-ares, BellSoft Hardened Containers:25: c-ares, BellSoft Hardened Containers:stream: c-ares&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: c-ares, Alpaquita:stream: c-ares, BellSoft Hardened Containers:25: c-ares, BellSoft Hardened Containers:stream: c-ares&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-69186</guid>
    </item>
    <item>
      <title>EUVD-2026-372380</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372380</link>
      <description>EUVD-2026-372380</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372380</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69186</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69186</link>
      <description>&lt;p&gt;c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69186</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-69186 — c-ares: Memory-amplification denial of service via unvalidated DNS header record counts</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-69186</link>
      <description>msrc_CVE-2026-69186</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-69186</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11593-1 — c-ares-devel-1.34.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11593-1</link>
      <description>&lt;p&gt;c-ares-devel-1.34.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;c-ares-devel-1.34.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11593-1</guid>
    </item>
    <item>
      <title>RHSA-2026:40574 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:40574</link>
      <description>&lt;p&gt;c-ares: c-ares: CPU exhaustion denial of service via unbounded DNS name compression pointer chains c-ares: c-ares: Denial of Service via unvalidated DNS header record counts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;c-ares: c-ares: CPU exhaustion denial of service via unbounded DNS name compression pointer chains c-ares: c-ares: Denial of Service via unvalidated DNS header record counts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:40574</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23364-1 — Security update for c-ares</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23364-1</link>
      <description>&lt;p&gt;Security update for c-ares&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for c-ares&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23364-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-69186</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: c-ares, Ubuntu:Pro:18.04:LTS: c-ares, Ubuntu:20.04:LTS: c-ares, Ubuntu:22.04:LTS: c-ares, Ubuntu:24.04:LTS: c-ares, Ubuntu:26.04:LTS: c-ares&lt;/p&gt;
&lt;p&gt;c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: c-ares, Ubuntu:Pro:18.04:LTS: c-ares, Ubuntu:20.04:LTS: c-ares, Ubuntu:22.04:LTS: c-ares, Ubuntu:24.04:LTS: c-ares, Ubuntu:26.04:LTS: c-ares&lt;/p&gt;
&lt;p&gt;c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69186</guid>
    </item>
  </channel>
</rss>
