Reachable assertion in Avahi - CVE-2025-68468
Published: April 24, 2026
Avahi
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in lookup_multicast_callback when processing unsolicited multicast DNS announcements containing CNAME resource records that point to records with short TTLs. A remote attacker can send a specially crafted announcement to cause a denial of service.
User interaction is required because exploitation depends on a record browser browsing for the targeted service type.