Vulnerabilities in the ConnMan network configurator and the DNS library c-ares.

A vulnerability (CVE-2025-32743) has been discovered in the network configurator ConnMan, which is widely used in embedded Linux systems, automotive platforms, and Internet of Things devices. This vulnerability could potentially lead to code execution when processing specially crafted responses from the DNS server. The issue has been assigned a critical severity level (9.1 out of 10). The vulnerability is present up to the current release of ConnMan 1.44 and remains unpatched.

The vulnerability exists in the DNS proxy implementation and is caused by the fact that when processing a DNS response with the TC (Truncated) bit, the lookup string in the ns_resolv function remains empty or has a NULL value. This subsequently leads to a buffer overflow due to incorrect size calculations of the data copied using the memcpy function.

Additionally, a vulnerability (CVE-2025-31498) has been noted in the c-ares library, which is designed for sending DNS queries asynchronously. This vulnerability is caused by accessing already freed memory (use-after-free) in the DNS server response handling function.

The issue arises because, in the event of a connection drop, there may be a situation where the connection descriptor has already been freed, but the read_answers() function considers it still available when excluding other requests from the queue. Exploiting the vulnerability is complicated by the fact that the attacker must control the DNS server used for resolving and create conditions that cause the send()/write() calls to fail, which is theoretically possible by flooding the victim with ICMP UNREACHABLE packets.

This vulnerability can be exploited to attack projects using the c-ares library. For example, c-ares is used in Node.js, sssd, apt-cacher-ng, Wireshark, pgbouncer, shadowsocks, Zephyr, sysdig, and frr. The issue appears starting from release 1.32.3 (July 2024) and is resolved in c-ares update 1.34.5. Tracking the resolution of the vulnerability in distributions can be done on the following pages: Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster