{"id":"CLSA-2025-1744721593","summary":"c-ares: Fix of 4 CVEs","details":"- CVE-2024-25629: fix invalid memory read issue in ares__read_line()\n- CVE-2023-31130: fix buffer underflow in ares_inet_net_pton() for certain ipv6\n  addresses\n- CVE-2023-31147: fix issue of using weak random numbers in DNS query ids by\n  replacing rand() with a modern OS-provided CSPRNG like arc4random()\n- CVE-2023-31124: prevent fallback to rand() for entropy generation\n  which could allow an attacker to take advantage of the lack of entropy by not\n  using a CSPRNG.","modified":"2026-05-27T11:36:11.351342647Z","published":"2025-04-15T12:53:19Z","upstream":["CVE-2023-31124","CVE-2023-31130","CVE-2023-31147","CVE-2024-25629"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/almalinux9.2-esu/CLSA-2025-1744721593.html"}],"affected":[{"package":{"name":"c-ares","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/c-ares?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.17.1-5.el9_2.1.tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1744721593.json"}},{"package":{"name":"c-ares-devel","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/c-ares-devel?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.17.1-5.el9_2.1.tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1744721593.json"}}],"schema_version":"1.7.5"}