CVE-2025-68471: Avahi has a reachable assertion in lookup_start
Avahi has a reachable assertion in lookupstart
Other sources
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68471?
CVE-2025-68471 is considered a moderate severity vulnerability due to its potential to crash the avahi-daemon.
How do I fix CVE-2025-68471?
To fix CVE-2025-68471, upgrade the avahi-daemon to version 0.9-rc3 or later to mitigate the vulnerability.
What software is affected by CVE-2025-68471?
CVE-2025-68471 affects the avahi-daemon version 0.9-rc2 and earlier.
What kind of attack is associated with CVE-2025-68471?
The attack associated with CVE-2025-68471 involves sending two unsolicited announcements with CNAME resource records in quick succession.
What happens if CVE-2025-68471 is exploited?
Exploitation of CVE-2025-68471 can lead to the crashing of the avahi-daemon, disrupting service discovery on the local network.