Reachable assertion in Avahi - CVE-2025-68471
Published: April 24, 2026
Avahi
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in lookup_start when processing unsolicited multicast DNS announcements with CNAME resource records. A remote attacker can send two specially crafted unsolicited announcements to cause a denial of service.
The issue affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, and user interaction is required.