CVE-2025-68276 on CTRL-OS 24.05
Packages: avahi
Status: In Progress
CVE Information
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This can be done by either calling the RecordBrowserNew method directly or creating hostname/address/service resolvers/browsers that create those browsers internally themselves.
Updates
2026-04-07 23:53 CEST
Metadata changes:
- Status for package
avahi: “In Progress”
2026-04-07 23:26 CEST
Metadata changes:
- Status for package
avahi: “Plausible”
2026-04-07 16:53 CEST
Metadata changes:
- Status for package
avahi: “Acknowledged”