CVE-2025-68468: Avahi has a reachable assertion in lookup_multicast_callback
Avahi has a reachable assertion in lookupmulticastcallback
Other sources
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68468?
CVE-2025-68468 is considered a critical vulnerability due to the potential for the avahi-daemon to be crashed remotely.
How do I fix CVE-2025-68468?
To fix CVE-2025-68468, upgrade Avahi to version 0.9-rc3 or later.
What software is affected by CVE-2025-68468?
CVE-2025-68468 affects Avahi versions up to and including 0.9-rc2.
What is the potential impact of CVE-2025-68468?
The potential impact of CVE-2025-68468 includes denial of service as the avahi-daemon can be crashed by malicious input.
Is CVE-2025-68468 an exploitable vulnerability?
Yes, CVE-2025-68468 can be exploited by sending unsolicited multicast announcements containing specific CNAME resource records.