Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1442-1

Опубликовано: 17 апр. 2026
Источник: suse-cvrf

Описание

Security update for avahi

This update for avahi fixes the following issue:

  • CVE-2026-24401: avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record (bsc#1257235).

Список пакетов

Image SLES12-SP5-Azure-BYOS
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-Azure-HPC-BYOS
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-Azure-HPC-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-Azure-SAP-BYOS
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-Azure-SAP-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-Azure-Standard-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-EC2-BYOS
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-EC2-ECS-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-EC2-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-EC2-SAP-BYOS
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-EC2-SAP-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-GCE-BYOS
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-GCE-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-GCE-SAP-BYOS
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-GCE-SAP-On-Demand
libavahi-client3-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
avahi-0.6.32-32.39.1
avahi-compat-howl-devel-0.6.32-32.39.1
avahi-compat-mDNSResponder-devel-0.6.32-32.39.1
avahi-lang-0.6.32-32.39.1
avahi-utils-0.6.32-32.39.1
libavahi-client3-0.6.32-32.39.1
libavahi-client3-32bit-0.6.32-32.39.1
libavahi-common3-0.6.32-32.39.1
libavahi-common3-32bit-0.6.32-32.39.1
libavahi-core7-0.6.32-32.39.1
libavahi-devel-0.6.32-32.39.1
libdns_sd-0.6.32-32.39.1
libdns_sd-32bit-0.6.32-32.39.1

Описание

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., "h.local" as a CNAME for "h.local"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:libavahi-client3-0.6.32-32.39.1
Image SLES12-SP5-Azure-BYOS:libavahi-common3-0.6.32-32.39.1
Image SLES12-SP5-Azure-HPC-BYOS:libavahi-client3-0.6.32-32.39.1
Image SLES12-SP5-Azure-HPC-BYOS:libavahi-common3-0.6.32-32.39.1

Ссылки
Уязвимость SUSE-SU-2026:1442-1