{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-33630","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-03-23T14:24:11.618Z","datePublished":"2026-09-03T18:42:28.783Z","dateUpdated":"2026-09-05T02:00:52.338Z"},"containers":{"cna":{"title":"c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP","problemTypes":[{"descriptions":[{"cweId":"CWE-415","lang":"en","description":"CWE-415: Double Free","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-416","lang":"en","description":"CWE-416: Use After Free","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"name":"https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542","tags":["x_refsource_CONFIRM"],"url":"https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542"},{"name":"https://github.com/c-ares/c-ares/pull/1237","tags":["x_refsource_MISC"],"url":"https://github.com/c-ares/c-ares/pull/1237"},{"name":"https://github.com/c-ares/c-ares/commit/1fa3b86a0b8d18fe7b60f3228a01d770feb026bc","tags":["x_refsource_MISC"],"url":"https://github.com/c-ares/c-ares/commit/1fa3b86a0b8d18fe7b60f3228a01d770feb026bc"},{"name":"https://github.com/c-ares/c-ares/commit/d823199b688052dcdc1646f2ab4cb8c16b1c644a","tags":["x_refsource_MISC"],"url":"https://github.com/c-ares/c-ares/commit/d823199b688052dcdc1646f2ab4cb8c16b1c644a"},{"name":"https://github.com/c-ares/c-ares/releases/tag/v1.34.7","tags":["x_refsource_MISC"],"url":"https://github.com/c-ares/c-ares/releases/tag/v1.34.7"}],"affected":[{"vendor":"c-ares","product":"c-ares","versions":[{"version":">= 1.32.3, < 1.34.7","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-09-03T20:04:36.574Z"},"descriptions":[{"lang":"en","value":"c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7."}],"source":{"advisory":"GHSA-6wfj-rwm7-3542","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-05T02:00:43.010024Z","id":"CVE-2026-33630","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-05T02:00:52.338Z"}}]}}