Back

HIGH

pycares has a Use-After-Free Vulnerability

Published Jun 20, 2025

Description

pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and name resolutions asynchronously. Prior to version 4.9.0, pycares is vulnerable to a use-after-free condition that occurs when a Channel object is garbage collected while DNS queries are still pending. This results in a fatal Python error and interpreter crash. The vulnerability has been fixed in pycares 4.9.0 by implementing a safe channel destruction mechanism.

Affected products

Remediation

Red Hat mitigation

To mitigate this flaw avoid creating Channel objects per-request.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jun 20, 2025
Updated Jun 20, 2025
Reserved May 28, 2025

CISA Vulnrichment

Updated Jun 20, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jun 16, 2025
Bugzilla 2373046

ENISA EUVD

Assigner GitHub_M
Published Jun 20, 2025
Updated Jun 20, 2025

GitHub

No data