CVE-2025-68468
published 2026-01-12CVE-2025-68468: Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.33%
25.3th percentile
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avahi | avahi | < 0.9 | 0.9 |
| avahi | avahi | <= 0.9-rc2 | — |
| avahi | avahi | — | — |
| avahi | avahi | >= 0 < 0.8-18 | 0.8-18 |
| avahi | avahi | >= 0 < 0.8-5ubuntu5.4 | 0.8-5ubuntu5.4 |
| avahi | avahi | >= 0 < 0.8-13ubuntu6.1 | 0.8-13ubuntu6.1 |
| avahi | avahi | >= 0 < 0.8-16ubuntu3.1 | 0.8-16ubuntu3.1 |
| avahi | avahi | >= 0 < 0.6.31-4ubuntu1.3+esm4 | 0.6.31-4ubuntu1.3+esm4 |
| avahi | avahi | >= 0 < 0.6.32~rc+dfsg-1ubuntu2.3+esm4 | 0.6.32~rc+dfsg-1ubuntu2.3+esm4 |
| avahi | avahi | >= 0 < 0.7-3.1ubuntu1.3+esm3 | 0.7-3.1ubuntu1.3+esm3 |
| avahi | avahi | >= 0 < 0.7-4ubuntu7.3+esm1 | 0.7-4ubuntu7.3+esm1 |
| debian | avahi | < avahi 0.8-18 (forky) | avahi 0.8-18 (forky) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Avahi vulnerabilities
vendor_ubuntu·2026-01-19·CVSS 5.5
CVE-2025-68471 [MEDIUM] Avahi vulnerabilities
Title: Avahi vulnerabilities
Summary: Several security issues were fixed in Avahi.
It was discovered that Avahi incorrectly terminated when processing browser
records with wide-area disabled. An attacker could possibly use this issue
to cause Avahi to crash, resulting in a denial of service. (CVE-2025-68276)
It was discovered that Avahi incorrectly terminated when processing
unsolicited CNAME records pointing to resource records with short TTLs. An
attacker could possibly use this issue to cause Avahi to crash, resulting
in a denial of service. (CVE-2025-68468)
It was discovered that Avahi incorrectly terminated when processing
unsolicited CNAME records in quick succession. An attacker could possibly
use this issue to cause Avahi to crash, resulting in a denial of service.
(CVE-2025-68
Red Hat
avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements
vendor_redhat·2026-01-12·CVSS 6.5
CVE-2025-68468 [MEDIUM] CWE-617 avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements
avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
A flaw was found in Avahi. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted unsolicited announcements containing CNAME resource records. These records, when pointing to other resource records with short Time-To-Live (TTL) values, can lead to the `avahi-daemon` crashing once they expire. This vulnerability impacts the availability of services relying on Avahi's servi
Debian
CVE-2025-68468: avahi - Avahi is a system which facilitates service discovery on a local network via the...
vendor_debian·2025·CVSS 6.5
CVE-2025-68468 [MEDIUM] CVE-2025-68468: avahi - Avahi is a system which facilitates service discovery on a local network via the...
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.8-18)
sid: resolved (fixed in 0.8-18)
trixie: open
OSV
avahi vulnerabilities
osv·2026-01-19·CVSS 5.5
CVE-2025-68276 [MEDIUM] avahi vulnerabilities
avahi vulnerabilities
It was discovered that Avahi incorrectly terminated when processing browser
records with wide-area disabled. An attacker could possibly use this issue
to cause Avahi to crash, resulting in a denial of service. (CVE-2025-68276)
It was discovered that Avahi incorrectly terminated when processing
unsolicited CNAME records pointing to resource records with short TTLs. An
attacker could possibly use this issue to cause Avahi to crash, resulting
in a denial of service. (CVE-2025-68468)
It was discovered that Avahi incorrectly terminated when processing
unsolicited CNAME records in quick succession. An attacker could possibly
use this issue to cause Avahi to crash, resulting in a denial of service.
(CVE-2025-68471)
OSV
CVE-2025-68468: Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite
osv·2026-01-12·CVSS 6.5
CVE-2025-68468 [MEDIUM] CVE-2025-68468: Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-68468 avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements
bugzilla·2026-01-12·CVSS 6.5
CVE-2025-68468 [MEDIUM] CVE-2025-68468 avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements
CVE-2025-68468 avahi: Avahi: Denial of Service via crafted mDNS/DNS-SD announcements
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
Wiz
CVE-2026-34933 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-34933 [MEDIUM] CVE-2026-34933 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34933 :
Avahi vulnerability analysis and mitigation
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.
Source : NVD
## 5.5
Score
Published April 3, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Avahi
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
avahi-libs
avahi-qt4-devel
Sources
NVD
Chainguard Has Fix Added at: Apr 05,
Wiz
CVE-2025-59529 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2025-59529 [MEDIUM] CVE-2025-59529 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59529 :
Avahi vulnerability analysis and mitigation
CLIENTS_MAX
server_work()
accept()
client_new()
n_clients
*.local.
/run/avahi-daemon/socket
Source : NVD
## 5.5
Score
Published December 18, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Avahi
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
avahi
avahi-compat-howl-devel
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Severity MEDIUM No Fix Added at: Jan 18, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Chainguard Has Fix Added at: Dec 21, 2025
D
Wiz
CVE-2025-68276 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2025-68276 [MEDIUM] CVE-2025-68276 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68276 :
Avahi vulnerability analysis and mitigation
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling
the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.
Source : NVD
## 5.5
Score
Published January 12, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Avahi
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Pe
Wiz
CVE-2025-68471 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-68471 [MEDIUM] CVE-2025-68471 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68471 :
Avahi vulnerability analysis and mitigation
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.
Source : NVD
## 6.5
Score
Published January 12, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Avahi
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python313-avahi
libavahi-core7
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21 Severity MEDIUM N
Wiz
CVE-2025-68468 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-68468 [MEDIUM] CVE-2025-68468 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68468 :
Avahi vulnerability analysis and mitigation
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
Source : NVD
## 6.5
Score
Published January 12, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Avahi
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
avahi-ui-tools
cpe:2.3:a:avahi:avahi
Sources
Alpine
Wiz
CVE-2026-24401 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-24401 [MEDIUM] CVE-2026-24401 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24401 :
Avahi vulnerability analysis and mitigation
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., "h.local" as a CNAME for "h.local"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524.
Source : NVD
## 6.5
2026-01-12
Published