Back to Database
Status published
Medium
CVE-2025-68471
Avahi has a reachable assertion in lookup_start
Vulnerability Description
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68471
Credits & Attribution
No credits recorded in the NVD database.
References
More from avahi
View All →CVE-2025-68468
Avahi has a reachable assertion in lookup_multicast_callback
Medium
6.5
CVE-2025-68276
Avahi has a reachable assertion in avahi_wide_area_scan_cache
Medium
5.5
CVE-2025-59529
simple protocol server ignores accepts unlimited connections and logs failures without limit
Medium
5.5
CVE-2021-26720
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed...
High
7.8
CVE-2017-6519
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to...
Unknown
0
Affected Vendor
avahi
View all reports →Affected Software
avahi
Vulnerable Versions:
<= 0.9-rc2
Timeline
Official Publish:
January 12th, 2026
Last Modified:
January 12th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H