-
Notifications
You must be signed in to change notification settings - Fork 125
Open
Labels
bugSomething isn't workingSomething isn't working
Description
Description
While working on the fixinventory project, we identified a critical vulnerability in the pycares package, which provides Python bindings for the c-ares asynchronous DNS library (this dependency used by fixinventory). The issue, disclosed as a use-after-free vulnerability, arises when the Channel object is garbage collected while DNS queries are still pending, potentially leading to fatal crashes or undefined behavior.
Version
5.29.3
Environment
No response
Steps to Reproduce
No response
Logs
Additional Context
No response
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working