Release date:
2026-08-25 13:12:41 UTC
Description:
* SECURITY UPDATE: denial of service via a 0-length UDP packet
- debian/patches/CVE-2023-32067.patch: in read_udp_packets() in
ares_process.c, treat a 0-length UDP read as a 0-length packet and keep
reading instead of tearing the server connection down; only a negative
return value is now an error, and an answer from a mismatched address
no longer stops the read loop.
- CVE-2023-32067
Updated packages:
-
libc-ares-dev_1.14.0-1ubuntu0.2+tuxcare.els1_amd64.deb
sha:ac0cd447d3b574d2a08a7015829f06e766bc0e04
-
libc-ares2_1.14.0-1ubuntu0.2+tuxcare.els1_amd64.deb
sha:ac5d6d4c9fb2845c87227aa22ef249ac8f336963
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.