c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-400"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69186.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-69186.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "339369170279688869394972447116353873681",
"length": 1975
},
"id": "CVE-2026-69186-03106c5a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab",
"target": {
"file": "src/lib/record/ares_dns_parse.c",
"function": "ares_dns_parse_header"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"269745032999509763615118565117448913611",
"293850083987775466205461459497353455979",
"323010113770663544280306504698269929440",
"30681434477766079920299812049078742637",
"38929257534299927680856913954246546348",
"15895386558806833721634587351085961895",
"124583247596904972311902091601606185919",
"59145353781277769958429907150297724971",
"185964326092560203476263515832635856067",
"5163151457131041087841222716786088906",
"226803838471376103552112412834119684715",
"95349107419783900172797516646485645226",
"316101072733228499413168884574648477245",
"124583247596904972311902091601606185919",
"208406617252468407765357363806351664847",
"214868768765460906184885095253828154881",
"197199470108670351154919151783174798803",
"266151619187248766745223437364952829851",
"323630750925285021174066480995849323975",
"293112365652976552277499496391485830546",
"124583247596904972311902091601606185919",
"72688991973933606185779345763108035723",
"303764570121988436663674128373546599905",
"254719075592665960425533569434171579843",
"3691270663326971301145206482899743434",
"289174478929386660407025304800871917030",
"317829815559797888745331349974067007101",
"192093125591080348095403894980793635153",
"146547429792180302822249306634742035247",
"991938742186947232412904668194235179",
"219054902886563942771950554648557493340"
],
"threshold": 0.9
},
"id": "CVE-2026-69186-9c5f528d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/e47c203f91cd8b749c8736bc18d75a31ffdec8f4",
"target": {
"file": "src/lib/record/ares_dns_parse.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"292947636881127679123105674089199271794",
"161213211813900988351898049535261271704"
],
"threshold": 0.9
},
"id": "CVE-2026-69186-a0b6b35f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab",
"target": {
"file": "test/ares-test-parse.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "229522228889724405761407632642095855034",
"length": 1381
},
"id": "CVE-2026-69186-b97ab270",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/e47c203f91cd8b749c8736bc18d75a31ffdec8f4",
"target": {
"file": "src/lib/record/ares_dns_parse.c",
"function": "ares_dns_parse_buf"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"292947636881127679123105674089199271794",
"161213211813900988351898049535261271704"
],
"threshold": 0.9
},
"id": "CVE-2026-69186-ca503a7d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/e47c203f91cd8b749c8736bc18d75a31ffdec8f4",
"target": {
"file": "test/ares-test-parse.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"269745032999509763615118565117448913611",
"293850083987775466205461459497353455979",
"323010113770663544280306504698269929440",
"30681434477766079920299812049078742637",
"38929257534299927680856913954246546348",
"15895386558806833721634587351085961895",
"124583247596904972311902091601606185919",
"59145353781277769958429907150297724971",
"185964326092560203476263515832635856067",
"5163151457131041087841222716786088906",
"226803838471376103552112412834119684715",
"95349107419783900172797516646485645226",
"316101072733228499413168884574648477245",
"124583247596904972311902091601606185919",
"208406617252468407765357363806351664847",
"214868768765460906184885095253828154881",
"197199470108670351154919151783174798803",
"266151619187248766745223437364952829851",
"323630750925285021174066480995849323975",
"293112365652976552277499496391485830546",
"124583247596904972311902091601606185919",
"72688991973933606185779345763108035723",
"303764570121988436663674128373546599905",
"254719075592665960425533569434171579843",
"3691270663326971301145206482899743434",
"289174478929386660407025304800871917030",
"317829815559797888745331349974067007101",
"192093125591080348095403894980793635153",
"146547429792180302822249306634742035247",
"991938742186947232412904668194235179",
"219054902886563942771950554648557493340"
],
"threshold": 0.9
},
"id": "CVE-2026-69186-cc27f06f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab",
"target": {
"file": "src/lib/record/ares_dns_parse.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "229522228889724405761407632642095855034",
"length": 1381
},
"id": "CVE-2026-69186-d9585494",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab",
"target": {
"file": "src/lib/record/ares_dns_parse.c",
"function": "ares_dns_parse_buf"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "339369170279688869394972447116353873681",
"length": 1975
},
"id": "CVE-2026-69186-e3303cda",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/c-ares/c-ares/commit/e47c203f91cd8b749c8736bc18d75a31ffdec8f4",
"target": {
"file": "src/lib/record/ares_dns_parse.c",
"function": "ares_dns_parse_header"
}
}
]
"2026-09-20T08:19:49Z"