Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68468

Опубликовано: 12 янв. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.

A flaw was found in Avahi. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted unsolicited announcements containing CNAME resource records. These records, when pointing to other resource records with short Time-To-Live (TTL) values, can lead to the avahi-daemon crashing once they expire. This vulnerability impacts the availability of services relying on Avahi's service discovery.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10avahiFix deferred
Red Hat Enterprise Linux 6avahiFix deferred
Red Hat Enterprise Linux 7avahiFix deferred
Red Hat Enterprise Linux 8avahiFix deferred
Red Hat Enterprise Linux 9avahiFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesavahi-main-0.9~rc4-0.1.hum1FixedRHSA-2026:1131628.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2428714avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements

EPSS

Процентиль: 27%
0.00344
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
7 месяцев назад

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.

CVSS3: 6.5
nvd
7 месяцев назад

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.

CVSS3: 6.5
msrc
7 месяцев назад

Avahi has a reachable assertion in lookup_multicast_callback

CVSS3: 6.5
debian
7 месяцев назад

Avahi is a system which facilitates service discovery on a local netwo ...

CVSS3: 6.5
fstec
7 месяцев назад

Уязвимость системы обнаружения сервисов в локальной сети Avahi, связанная с недостатком использования функции assert(), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00344
Низкий

6.5 Medium

CVSS3