Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47184

Опубликовано: 17 июл. 2026
Источник: redhat
CVSS3: 6.5

Описание

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, _expire_heap, and service_cache without a cap, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to multicast valid mDNS responses with unique names and cause memory exhaustion, slower cache lookups, slower async_expire passes, and broken discovery, registration, and ServiceBrowser callbacks. This issue is fixed in version 0.149.7.

A flaw was found in Zeroconf, a Python library for multicast DNS service discovery. An unauthenticated attacker on the local network can send specially crafted multicast DNS responses. This can lead to uncontrolled memory growth, causing memory exhaustion and significantly degrading the performance of the service, ultimately resulting in a denial of service (DoS).

Отчет

Zeroconf is a pure Python implementation of multicast DNS (mDNS) service discovery. Prior to 0.149.7, every mDNS response record is inserted into the internal cache and expiration structures with no cap, so an attacker can multicast a stream of responses with unique names to exhaust memory and degrade cache performance, resulting in denial of service impact for unauthenticated hosts on the local network segment (UDP/5353, 224.0.0.251 / ff02::fb). Exploitation requires the attacker to be on the same local link as the affected host, consistent with Red Hat's Adjacent (AV:A) attack vector scoring. This issue is fixed upstream in zeroconf 0.149.7. Red Hat's CVSS score matches the vendor/CVE.org assessment for this flaw. This flaw is one of a batch of related Zeroconf issues discovered and fixed close together (CVE-2026-47180, CVE-2026-47183, CVE-2026-47184, CVE-2026-48045, CVE-2026-48487); all affect the same Red Hat product streams in the same way and were triaged consistently as a batch.

Меры по смягчению последствий

Upgrade to zeroconf 0.149.7 or later once packaged in the affected Red Hat product. Where upgrading isn't immediately possible, restricting the affected host's exposure to the local network segment (network segmentation or firewalling multicast DNS traffic on UDP/5353) reduces the practical attack surface, since exploitation requires local-link access.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2501854zeroconf: Zeroconf: Denial of Service via uncontrolled memory growth

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
20 дней назад

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, _expire_heap, and service_cache without a cap, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to multicast valid mDNS responses with unique names and cause memory exhaustion, slower cache lookups, slower async_expire passes, and broken discovery, registration, and ServiceBrowser callbacks. This issue is fixed in version 0.149.7.

CVSS3: 6.5
nvd
20 дней назад

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, _expire_heap, and service_cache without a cap, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to multicast valid mDNS responses with unique names and cause memory exhaustion, slower cache lookups, slower async_expire passes, and broken discovery, registration, and ServiceBrowser callbacks. This issue is fixed in version 0.149.7.

CVSS3: 6.5
debian
20 дней назад

Zeroconf is a pure Python implementation of multicast DNS service disc ...

CVSS3: 6.5
github
2 месяца назад

zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood

suse-cvrf
около 1 месяца назад

Security update for python-zeroconf

6.5 Medium

CVSS3