CVE-2026-34933Reachable Assertion in Avahi

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 94.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3

Description

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Patches

🔴Vulnerability Details

1
OSV
CVE-2026-34933: Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite2026-04-03

📋Vendor Advisories

3
Red Hat
avahi: avahi-daemon: Avahi: Denial of Service via D-Bus method call2026-04-03
Microsoft
Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon2026-04-02
Debian
CVE-2026-34933: avahi - Avahi is a system which facilitates service discovery on a local network via the...2026

🕵️Threat Intelligence

6
Wiz
CVE-2026-34933 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-59529 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-68276 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-68471 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-68468 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-34933 avahi: avahi-daemon: Avahi: Denial of Service via D-Bus method call2026-04-03