Uncontrolled Recursion in Avahi - CVE-2024-2699
Published: April 24, 2026
Avahi
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in lookup_handle_cname when processing unsolicited announcements with recursive CNAME resource records. A remote attacker can send a specially crafted multicast DNS announcement to cause a denial of service.
User interaction is required, and the issue affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly.