Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20110-1

Опубликовано: 26 янв. 2026
Источник: suse-cvrf

Описание

Security update for avahi

This update for avahi fixes the following issues:

  • CVE-2025-68276: Fixed refuse to create wide-area record browsers when wide-area is off (bsc#1256498)
  • CVE-2025-68471: Fixed DoS bug by changing assert to return (bsc#1256500)
  • CVE-2025-68468: Fixed DoS bug by removing incorrect assertion (bsc#1256499)

Список пакетов

openSUSE Leap 16.0
avahi-0.8-160000.4.1
avahi-autoipd-0.8-160000.4.1
avahi-compat-howl-devel-0.8-160000.4.1
avahi-compat-mDNSResponder-devel-0.8-160000.4.1
avahi-lang-0.8-160000.4.1
avahi-utils-0.8-160000.4.1
avahi-utils-gtk-0.8-160000.4.1
libavahi-client3-0.8-160000.4.1
libavahi-common3-0.8-160000.4.1
libavahi-core7-0.8-160000.4.1
libavahi-devel-0.8-160000.4.1
libavahi-glib-devel-0.8-160000.4.1
libavahi-glib1-0.8-160000.4.1
libavahi-gobject-devel-0.8-160000.4.1
libavahi-gobject0-0.8-160000.4.1
libavahi-libevent1-0.8-160000.4.1
libavahi-qt6-1-0.8-160000.4.1
libavahi-qt6-devel-0.8-160000.4.1
libavahi-ui-gtk3-0-0.8-160000.4.1
libdns_sd-0.8-160000.4.1
libhowl0-0.8-160000.4.1
python3-avahi-gtk-0.8-160000.4.1
python313-avahi-0.8-160000.4.1
typelib-1_0-Avahi-0_6-0.8-160000.4.1

Описание

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.


Затронутые продукты
openSUSE Leap 16.0:avahi-0.8-160000.4.1
openSUSE Leap 16.0:avahi-autoipd-0.8-160000.4.1
openSUSE Leap 16.0:avahi-compat-howl-devel-0.8-160000.4.1
openSUSE Leap 16.0:avahi-compat-mDNSResponder-devel-0.8-160000.4.1

Ссылки

Описание

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.


Затронутые продукты
openSUSE Leap 16.0:avahi-0.8-160000.4.1
openSUSE Leap 16.0:avahi-autoipd-0.8-160000.4.1
openSUSE Leap 16.0:avahi-compat-howl-devel-0.8-160000.4.1
openSUSE Leap 16.0:avahi-compat-mDNSResponder-devel-0.8-160000.4.1

Ссылки

Описание

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.


Затронутые продукты
openSUSE Leap 16.0:avahi-0.8-160000.4.1
openSUSE Leap 16.0:avahi-autoipd-0.8-160000.4.1
openSUSE Leap 16.0:avahi-compat-howl-devel-0.8-160000.4.1
openSUSE Leap 16.0:avahi-compat-mDNSResponder-devel-0.8-160000.4.1

Ссылки