c-ares: bump to 1.34.6
authorHirokazu MORIKAWA <[email protected]>
Mon, 15 Dec 2025 08:42:33 +0000 (17:42 +0900)
committerHannu Nyman <[email protected]>
Mon, 15 Dec 2025 14:46:38 +0000 (15:46 +0100)
This is a security release.

Security:
* CVE-2025-31498. A use-after-free bug has been uncovered in read_answers() that was introduced in v1.32.3. Please see GHSA-6hxc-62jh-p29v
* CVE-2025-62408. A use-after-free bug has been uncovered in read_answers() that
was introduced in v1.32.3. Please see GHSA-jq53-42q6-pqr5

Signed-off-by: Hirokazu MORIKAWA <[email protected]>
(cherry picked from commit ebdb9536a9a0063f92efd63b529d7c9bd0d838c4)

libs/c-ares/Makefile

index eafa3ff058fb8347dd1427abef71417ca5ea366f..8e132851ed0894c0c3e17295d6a25e2d8428645a 100644 (file)
@@ -9,12 +9,12 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=c-ares
-PKG_VERSION:=1.33.1
+PKG_VERSION:=1.34.6
 PKG_RELEASE:=1
 
 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.gz
 PKG_SOURCE_URL:=https://github.com/c-ares/c-ares/releases/download/v$(PKG_VERSION)
-PKG_HASH:=06869824094745872fa26efd4c48e622b9bd82a89ef0ce693dc682a23604f415
+PKG_HASH:=912dd7cc3b3e8a79c52fd7fb9c0f4ecf0aaa73e45efda880266a2d6e26b84ef5
 
 PKG_LICENSE:=MIT
 PKG_LICENSE_FILES:=LICENSE.md