vulnerability
Alma Linux: CVE-2025-31498: Important: nodejs:22 security update (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:M/Au:N/C:P/I:P/A:C) | Apr 8, 2025 | May 9, 2025 | Apr 20, 2026 |
Description
c-ares is an asynchronous resolver library. From 1.32.3 through 1.34.4, there is a use-after-free in read_answers() when process_answer() may re-enqueue a query either due to a DNS Cookie Failure or when the upstream server does not properly support EDNS, or possibly on TCP queries if the remote closed the connection immediately after a response. If there was an issue trying to put that new transaction on the wire, it would close the connection handle, but read_answers() was still expecting the connection handle to be available to possibly dequeue other responses. In theory a remote attacker might be able to trigger this by flooding the target with ICMP UNREACHABLE packets if they also control the upstream nameserver and can return a result with one of those conditions, this has been untested. Otherwise only a local attacker might be able to change system behavior to make send()/write() return a failure condition. This vulnerability is fixed in 1.34.5.
Solutions
References
- CVE-2025-31498
- https://attackerkb.com/topics/CVE-2025-31498
- CWE-416
- EUVD-EUVD-2025-10377
- https://errata.almalinux.org/8/ALSA-2025-4459.html
- https://errata.almalinux.org/8/ALSA-2025-4461.html
- https://errata.almalinux.org/9/ALSA-2025-7426.html
- https://errata.almalinux.org/9/ALSA-2025-7433.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10377
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.