CVE-2023-38471
published 2023-11-02CVE-2023-38471: A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.33%
24.9th percentile
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avahi | avahi | < 0.9 | 0.9 |
| avahi | avahi | >= 0 < 0.8-5+deb11u3 | 0.8-5+deb11u3 |
| avahi | avahi | >= 0 < 0.8-10+deb12u1 | 0.8-10+deb12u1 |
| avahi | avahi | >= 0 < 0.8-14 | 0.8-14 |
| avahi | avahi | >= 0 < 0.8-14 | 0.8-14 |
| avahi | avahi | >= 0 < 0.7-4ubuntu7.3 | 0.7-4ubuntu7.3 |
| avahi | avahi | >= 0 < 0.8-5ubuntu5.2 | 0.8-5ubuntu5.2 |
| avahi | avahi | >= 0 < 0.6.31-4ubuntu1.3+esm3 | 0.6.31-4ubuntu1.3+esm3 |
| avahi | avahi | >= 0 < 0.6.32~rc+dfsg-1ubuntu2.3+esm3 | 0.6.32~rc+dfsg-1ubuntu2.3+esm3 |
| avahi | avahi | >= 0 < 0.7-3.1ubuntu1.3+esm2 | 0.7-3.1ubuntu1.3+esm2 |
| debian | avahi | < avahi 0.8-10+deb12u1 (bookworm) | avahi 0.8-10+deb12u1 (bookworm) |
| msrc | azl3_avahi_0.8-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_avahi_0.8-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_avahi_0.8-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian6.2MEDIUM
vendor_msrc6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_ubuntu6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
avahi vulnerabilities
osv·2023-11-20·CVSS 5.5
CVE-2023-38469 [MEDIUM] avahi vulnerabilities
avahi vulnerabilities
Evgeny Vereshchagin discovered that Avahi contained several reachable
assertions, which could lead to intentional assertion failures when
specially crafted user input was given. An attacker could possibly use
this issue to cause a denial of service. (CVE-2023-38469, CVE-2023-38470,
CVE-2023-38471, CVE-2023-38472, CVE-2023-38473)
OSV
CVE-2023-38471: A vulnerability was found in Avahi
osv·2023-11-02·CVSS 5.5
CVE-2023-38471 [MEDIUM] CVE-2023-38471: A vulnerability was found in Avahi
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
GHSA
GHSA-h3x3-j454-4phv: A vulnerability was found in Avahi
ghsa_unreviewed·2023-11-02
CVE-2023-38471 [MEDIUM] CWE-617 GHSA-h3x3-j454-4phv: A vulnerability was found in Avahi
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
Ubuntu
Avahi vulnerabilities
vendor_ubuntu·2023-11-20·CVSS 6.2
CVE-2023-38469 [MEDIUM] Avahi vulnerabilities
Title: Avahi vulnerabilities
Summary: Avahi could be made to crash if it received specially crafted
input.
Evgeny Vereshchagin discovered that Avahi contained several reachable
assertions, which could lead to intentional assertion failures when
specially crafted user input was given. An attacker could possibly use
this issue to cause a denial of service. (CVE-2023-38469, CVE-2023-38470,
CVE-2023-38471, CVE-2023-38472, CVE-2023-38473)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Reachable assertion in dbus_set_host_name
vendor_msrc·2023-11-14·CVSS 6.2
CVE-2023-38471 [MEDIUM] CWE-617 Reachable assertion in dbus_set_host_name
Reachable assertion in dbus_set_host_name
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.c
Red Hat
avahi: Reachable assertion in dbus_set_host_name
vendor_redhat·2023-04-26·CVSS 6.2
CVE-2023-38471 [MEDIUM] CWE-617 avahi: Reachable assertion in dbus_set_host_name
avahi: Reachable assertion in dbus_set_host_name
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
Package: avahi (Red Hat Enterprise Linux 6) - Out of support scope
Package: avahi (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2023-38471: avahi - A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set...
vendor_debian·2023·CVSS 6.2
CVE-2023-38471 [MEDIUM] CVE-2023-38471: avahi - A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set...
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
Scope: local
bookworm: resolved (fixed in 0.8-10+deb12u1)
bullseye: resolved (fixed in 0.8-5+deb11u3)
forky: resolved (fixed in 0.8-14)
sid: resolved (fixed in 0.8-14)
trixie: resolved (fixed in 0.8-14)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-11-02
Published