Reachable assertion in Avahi - CVE-2025-68276
Published: April 24, 2026
Avahi
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to reachable assertion in avahi_wide_area_scan_cache when creating a record browser with the AVAHI_LOOKUP_USE_WIDE_AREA flag while wide-area is disabled. A local user can create a crafted record browser request to cause a denial of service.
The issue causes avahi-daemon to terminate with SIGABRT.